4.3
    Medium

    CVE-2010-2273

    Last Modified: 15 Jun 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to dojo/resources/iframe_history.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, and util/buildscripts/jslib/buildUtil.js, as demonstrated by the (1) dojoUrl and (2) testUrl parameters to util/doh/runner.html.

    Source:Adam Bixby
    Published:14 Jun 2010
    5
    Medium

    CVE-2010-2266

    Last Modified: 11 Apr 2025

    nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.

    Source:Dr_IDE
    Published:14 Jun 2010
    4.3
    Medium

    CVE-2010-2265

    Last Modified: 21 Jul 2014

    Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm. NOTE: this can be leveraged with CVE-2010-1885 to execute arbitrary commands without user interaction.

    Source:Tavis Ormandy
    Published:14 Jun 2010
    5
    Medium

    CVE-2010-2263

    Last Modified: 9 Jan 2011

    nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.

    Source:Jose A. Vazquez
    Published:14 Jun 2010
    7.5
    High

    CVE-2010-2259

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the BF Survey (com_bfsurvey) component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

    Source:FL0RiX
    Published:9 Jun 2010
    7.5
    High

    CVE-2010-2257

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index_ie.php in Pay Per Minute Video Chat Script 2.0 and 2.1 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Source:R3d-D3V!L
    Published:9 Jun 2010
    4.3
    Medium

    CVE-2010-2256

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to videos.php.

    Source:R3d-D3V!L
    Published:9 Jun 2010
    7.5
    High

    CVE-2010-2255

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the BF Survey Pro (com_bfsurvey_pro) component before 1.3.1, BF Survey Pro Free (com_bfsurvey_profree) component 1.2.6, and BF Survey Basic component before 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:FL0RiX
    Published:9 Jun 2010
    7.5
    High

    CVE-2010-2254

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php.

    Source:R3d-D3V!L
    Published:9 Jun 2010
    5.1
    Medium

    CVE-2010-2246

    Last Modified: 29 Jul 2014

    feh before 1.8, when the --wget-timestamp option is enabled, might allow remote attackers to execute arbitrary commands via shell metacharacters in a URL.

    Source:anonymous
    Published:26 May 2011
    9.3
    Critical

    CVE-2010-2204

    Last Modified: 30 Jun 2010

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.

    Source:LiquidWorm
    Published:29 Jun 2010
    9.3
    Critical

    CVE-2010-2201

    Last Modified: 16 Sept 2010

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content involving the (1) pushstring (0x2C) operator, (2) debugfile (0xF1) operator, and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2168.

    Source:Abysssec
    Published:29 Jun 2010
    9.3
    Critical

    CVE-2010-2168

    Last Modified: 23 Sept 2010

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content, involving the newfunction (0x44) operator and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2201.

    Source:Abysssec
    Published:29 Jun 2010
    6.5
    Medium

    CVE-2010-2159

    Last Modified: 14 Jul 2014

    Dameng DM Database Server allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors related to the SP_DEL_BAK_EXPIRED procedure in wdm_dll.dll, which triggers memory corruption.

    Source:Shennan Wang HuaweiSymantec SRT
    Published:7 Jun 2010
    5
    Medium

    CVE-2010-2156

    Last Modified: 3 Jul 2010

    ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID.

    Source:sid
    Published:1 Jun 2010
    4.3
    Medium

    CVE-2010-2154

    Last Modified: 14 Dec 2016

    Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: some of these details are obtained from third party information.

    Source:XroGuE
    Published:3 Jun 2010
    6.8
    Medium

    CVE-2010-2153

    Last Modified: 15 Jul 2014

    Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in cache/.

    Source:John Leitch
    Published:3 Jun 2010
    7.5
    High

    CVE-2010-2148

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pagina parameter to index.php.

    Source:Valentin
    Published:3 Jun 2010
    4.3
    Medium

    CVE-2010-2147

    Last Modified: 19 Dec 2016

    Cross-site scripting (XSS) vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the modveh parameter to index.php.

    Source:Valentin
    Published:3 Jun 2010
    7.5
    High

    CVE-2010-2146

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in banned.php in Visitor Logger allows remote attackers to execute arbitrary PHP code via a URL in the VL_include_path parameter.

    Source:bd0rk
    Published:3 Jun 2010
    4.3
    Medium

    CVE-2010-2144

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in signinform.php in Zeeways eBay Clone Auction Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information.

    Source:XroGuE
    Published:3 Jun 2010
    7.5
    High

    CVE-2010-2143

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the mode parameter.

    Source:AntiSecurity
    Published:3 Jun 2010
    7.5
    High

    CVE-2010-2142

    Last Modified: 11 Jul 2014

    SQL injection vulnerability in default.asp in Cyberhost allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:redst0rm
    Published:2 Jun 2010
    7.5
    High

    CVE-2010-2141

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in NITRO Web Gallery allows remote attackers to execute arbitrary SQL commands via the PictureId parameter in an open action.

    Source:cyberlog
    Published:2 Jun 2010
    6.8
    Medium

    CVE-2010-2138

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in ProMan 0.1.1 and earlier allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SESSION[userLang] parameter to (1) elisttasks.php, (2) managepmanagers.php, (3) manageusers.php, (4) helpfunc.php, (5) managegroups.php, (6) manageprocess.php, and (7) manageusersgroups.php.

    Source:cr4wl3r
    Published:2 Jun 2010
    7.5
    High

    CVE-2010-2137

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in _center.php in ProMan 0.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:cr4wl3r
    Published:2 Jun 2010
    7.5
    High

    CVE-2010-2135

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in login.php in HazelPress Lite 0.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) password fields.

    Source:cr4wl3r
    Published:2 Jun 2010
    7.5
    High

    CVE-2010-2134

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in login.php in Project Man 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.

    Source:cr4wl3r
    Published:2 Jun 2010
    7.5
    High

    CVE-2010-2133

    Last Modified: 10 May 2012

    SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942.

    Source:Easy Laster
    Published:2 Jun 2010
    4.3
    Medium

    CVE-2010-2130

    Last Modified: 8 Jun 2014

    Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global ARISg 5.0 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.

    Source:Yaniv Miron
    Published:2 Jun 2010
    6.8
    Medium

    CVE-2010-2129

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:Valentin
    Published:1 Jun 2010
    7.5
    High

    CVE-2010-2128

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the view parameter to index.php.

    Source:ALTBTA
    Published:1 Jun 2010
    7.5
    High

    CVE-2010-2127

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in gallery.php in JV2 Folder Gallery 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter.

    Source:Sn!pEr.S!Te Hacker
    Published:1 Jun 2010
    7.5
    High

    CVE-2010-2126

    Last Modified: 9 Jul 2014

    Multiple PHP remote file inclusion vulnerabilities in Snipe Gallery 3.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the cfg_admin_path parameter to (1) index.php, (2) view.php, (3) image.php, (4) search.php, (5) admin/index.php, (6) admin/gallery/index.php, (7) admin/gallery/view.php, (8) admin/gallery/gallery.php, (9) admin/gallery/image.php, and (10) admin/gallery/crop.php.

    Source:Sn!pEr.S!Te Hacker
    Published:1 Jun 2010
    7.5
    High

    CVE-2010-2124

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in firma.php in Bartels Schone ConPresso 4.0.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Gamoscu
    Published:1 Jun 2010
    6.8
    Medium

    CVE-2010-2122

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

    Source:ALTBTA
    Published:1 Jun 2010
    5
    Medium

    CVE-2010-2115

    Last Modified: 27 Sept 2016

    SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted read request.

    Source:Nullthreat
    Published:28 May 2010
    4.3
    Medium

    CVE-2010-2103

    Last Modified: 19 Dec 2016

    Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.

    Source:Richard Brain
    Published:21 May 2010
    10
    Critical

    CVE-2010-2102

    Last Modified: 11 Apr 2025

    Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Source:m-1-k-3
    Published:27 May 2010
    7.5
    High

    CVE-2010-2099

    Last Modified: 11 Apr 2025

    bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php, related to invocations of the toHTML method.

    Source:McFly
    Published:27 May 2010
    6.8
    Medium

    CVE-2010-2094

    Last Modified: 26 Jun 2017

    Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly handled by the (1) phar_stream_flush, (2) phar_wrapper_unlink, (3) phar_parse_url, or (4) phar_wrapper_open_url functions in ext/phar/stream.c; and the (5) phar_wrapper_open_dir function in ext/phar/dirstream.c, which triggers errors in the php_stream_wrapper_log_error function.

    Source:Stefan Esser
    Published:14 May 2010
    4.3
    Medium

    CVE-2010-2091

    Last Modified: 11 Apr 2025

    Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.

    Source:Praveen Darshanam
    Published:27 May 2010
    5
    Medium

    CVE-2010-2089

    Last Modified: 23 Jul 2014

    The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.

    Source:haypo
    Published:11 Jan 2010
    7.5
    High

    CVE-2010-2075

    Last Modified: 15 Jul 2011

    UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.

    Source:Metasploit
    Published:15 Jun 2010
    7.5
    High

    CVE-2010-2063

    Last Modified: 1 Dec 2016

    Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.

    Source:Metasploit
    Published:16 Jun 2010
    7.5
    High

    CVE-2010-2051

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in article.php in Debliteck DBCart allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:v3n0m
    Published:25 May 2010
    7.5
    High

    CVE-2010-2050

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:Xr0b0t
    Published:25 May 2010
    7.5
    High

    CVE-2010-2047

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in JE CMS 1.0.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewcategory action. NOTE: some of these details are obtained from third party information.

    Source:AntiSecurity
    Published:25 May 2010
    7.5
    High

    CVE-2010-2045

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

    Source:Chip d3 bi0s
    Published:25 May 2010
    7.5
    High

    CVE-2010-2044

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the Konsultasi (com_konsultasi) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in a detail action to index.php.

    Source:c4uR
    Published:25 May 2010