7.5
    High

    CVE-2010-2042

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in search.php in ECShop 2.7.2 allows remote attackers to execute arbitrary SQL commands via the encode parameter. NOTE: some of these details are obtained from third party information.

    Source:Jannock
    Published:25 May 2010
    4.3
    Medium

    CVE-2010-2040

    Last Modified: 9 Jul 2014

    Cross-site scripting (XSS) vulnerability in search.php in V-EVA Shopzilla Affiliate Script PHP allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Source:Andrea Bocchetti
    Published:25 May 2010
    6.8
    Medium

    CVE-2010-2039

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an Admin_Users action to index.php. NOTE: some of these details are obtained from third party information.

    Source:Giuseppe 'giudinvx' D'Inverno
    Published:25 May 2010
    2.1
    Low

    CVE-2010-2038

    Last Modified: 11 Jul 2014

    Cross-site scripting (XSS) vulnerability in include/tool/editing_files.php in gpEasy CMS 1.6.2 allows remote authenticated users, with Edit privileges, to inject arbitrary web script or HTML via the gpcontent parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:High-Tech Bridge SA
    Published:25 May 2010
    7.5
    High

    CVE-2010-2037

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Percha Downloads Attach (com_perchadownloadsattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:25 May 2010
    7.5
    High

    CVE-2010-2036

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:25 May 2010
    7.5
    High

    CVE-2010-2035

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:25 May 2010
    7.5
    High

    CVE-2010-2034

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:25 May 2010
    7.5
    High

    CVE-2010-2033

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Percha Multicategory Article (com_perchacategoriestree) component 0.6 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:25 May 2010
    4.3
    Medium

    CVE-2010-2032

    Last Modified: 9 Jul 2014

    Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) digest_realm or (2) digest_username parameters. NOTE: some of these details are obtained from third party information.

    Source:xuanmumu
    Published:24 May 2010
    7.2
    High

    CVE-2010-2031

    Last Modified: 11 Apr 2025

    KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x830020d4 on the KAVSafe device.

    Source:Xuanyuan Smart
    Published:24 May 2010
    10
    Critical

    CVE-2010-2028

    Last Modified: 11 Apr 2025

    Buffer overflow in k23productions TFTPUtil GUI (aka TFTPGUI) 1.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long transport mode.

    Source:Jeremiah Talamantes
    Published:24 May 2010
    6.8
    Medium

    CVE-2010-2025

    Last Modified: 11 Jul 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allow remote attackers to hijack the authentication of administrators for requests that (1) reset the modem, (2) erase the firmware, (3) change the administrative password, (4) install modified firmware, or (5) change the access level, as demonstrated by a request to goform/_aslvl.

    Source:Dan Rosenberg
    Published:26 May 2010
    6.9
    Medium

    CVE-2010-2020

    Last Modified: 24 Jun 2010

    sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount request.

    Source:Patroklos Argyroudis
    Published:28 May 2010
    5
    Medium

    CVE-2010-2018

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:vir0e5
    Published:24 May 2010
    7.5
    High

    CVE-2010-2016

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in details.php in Iceberg CMS allows remote attackers to execute arbitrary SQL commands via the p_id parameter.

    Source:cyberlog
    Published:24 May 2010
    6.8
    Medium

    CVE-2010-2015

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in LiSK CMS 4.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in a view_inbox action to cp/cp_messages.php or (2) the id parameter to cp/edit_email.php.

    Source:High-Tech Bridge SA
    Published:24 May 2010
    3.5
    Low

    CVE-2010-2008

    Last Modified: 3 Aug 2010

    MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.

    Source:Shane Bester
    Published:6 Jul 2010
    6.5
    Medium

    CVE-2010-2006

    Last Modified: 27 May 2014

    Directory traversal vulnerability in op/op.Login.php in LetoDMS (formerly MyDMS) 1.7.2 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Source:D. Fabian
    Published:20 May 2010
    7.5
    High

    CVE-2010-2005

    Last Modified: 28 May 2014

    Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the selected_language parameter to engine/inc/include/init.php, (2) the config[langs] parameter to engine/inc/help.php, (3) the config[lang] parameter to engine/ajax/pm.php, (4) and the _REQUEST[skin] parameter to engine/ajax/addcomments.php.

    Source:indoushka
    Published:20 May 2010
    9.3
    Critical

    CVE-2010-2004

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via the Skin parameter in the Options section of a skins file (.bsi), a different vulnerability than CVE-2009-1068.

    Source:Mert SARICA
    Published:20 May 2010
    4.3
    Medium

    CVE-2010-2003

    Last Modified: 5 Jul 2014

    Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject arbitrary web script or HTML via the mysql_host parameter.

    Source:High-Tech Bridge SA
    Published:20 May 2010
    6.8
    Medium

    CVE-2010-1999

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in OpenMairie Opencatalogue 1.024, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.

    Source:cr4wl3r
    Published:20 May 2010
    2.1
    Low

    CVE-2010-1997

    Last Modified: 6 Jul 2014

    Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "Article list" edit privileges, to inject arbitrary web script or HTML via the pealkiri parameter.

    Source:High-Tech Bridge SA
    Published:20 May 2010
    7.5
    High

    CVE-2010-1994

    Last Modified: 6 Jul 2014

    SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the q parameter in conjunction with a /news/search PATH_INFO.

    Source:Russ McRee
    Published:20 May 2010
    7.5
    High

    CVE-2010-1983

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:NoGe
    Published:19 May 2010
    5
    Medium

    CVE-2010-1982

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the JA Voice (com_javoice) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.

    Source:kaMtiEz
    Published:19 May 2010
    6.8
    Medium

    CVE-2010-1981

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:19 May 2010
    7.5
    High

    CVE-2010-1980

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in joomlaflickr.php in the Joomla Flickr (com_joomlaflickr) component 1.0.3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:19 May 2010
    6.8
    Medium

    CVE-2010-1979

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:19 May 2010
    7.5
    High

    CVE-2010-1977

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the J!WHMCS Integrator (com_jwhmcs) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:19 May 2010
    7.5
    High

    CVE-2010-1964

    Last Modified: 27 Oct 2016

    Buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified parameters to jovgraph.exe, aka ZDI-CAN-683.

    Source:bitform
    Published:17 Jun 2010
    10
    Critical

    CVE-2010-1961

    Last Modified: 24 Mar 2011

    Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified variables to jovgraph.exe, which are not properly handled in a call to the sprintf function.

    Source:Metasploit
    Published:10 Jun 2010
    10
    Critical

    CVE-2010-1960

    Last Modified: 24 Mar 2011

    Buffer overflow in the error handling functionality in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long, invalid option to jovgraph.exe.

    Source:Metasploit
    Published:10 Jun 2010
    7.5
    High

    CVE-2010-1957

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Love Factory (com_lovefactory) component 1.3.4 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:18 May 2010
    7.5
    High

    CVE-2010-1956

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Gadget Factory (com_gadgetfactory) component 1.0.0 and 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:AntiSecurity
    Published:18 May 2010
    7.5
    High

    CVE-2010-1955

    Last Modified: 15 Dec 2016

    Directory traversal vulnerability in the Deluxe Blog Factory (com_blogfactory) component 1.1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:18 May 2010
    7.5
    High

    CVE-2010-1954

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the iNetLanka Multiple root (com_multiroot) component 1.0 and 1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:AntiSecurity
    Published:18 May 2010
    7.5
    High

    CVE-2010-1953

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:18 May 2010
    7.5
    High

    CVE-2010-1952

    Last Modified: 15 Dec 2016

    Directory traversal vulnerability in the BeeHeard (com_beeheard) and BeeHeard Lite (com_beeheardlite) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:18 May 2010
    6.8
    Medium

    CVE-2010-1951

    Last Modified: 19 Jul 2017

    Multiple directory traversal vulnerabilities in 60cycleCMS allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the DOCUMENT_ROOT parameter to (1) news.php, (2) submitComment.php, and (3) sqlConnect.php.

    Source:eidelweiss
    Published:18 May 2010
    6.8
    Medium

    CVE-2010-1950

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the date_info parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Don Tukulesto
    Published:18 May 2010
    7.5
    High

    CVE-2010-1949

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:Don Tukulesto
    Published:18 May 2010
    6.8
    Medium

    CVE-2010-1948

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.

    Source:cr4wl3r
    Published:18 May 2010
    6.8
    Medium

    CVE-2010-1947

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in openMairie Openregistrecil 1.02, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter. NOTE: this may be related to CVE-2007-2069.

    Source:cr4wl3r
    Published:18 May 2010
    6.8
    Medium

    CVE-2010-1946

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in openMairie Openregistrecil 1.02, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) autorisation_normale.class.php, (2) collectivite.class.php, (3) dossier.class.php, (4) norme_simplifiee.class.php, (5) registre.class.php, (6) autorisation_unique.class.php, (7) demande_avis.class.php, (8) droit.class.php, (9) organisme.class.php, (10) service.class.php, (11) categorie_donnee.class.php, (12) destinataire.class.php, (13) profil.class.php, (14) tabdyn_visu.class.php, (15) categorie_personne.class.php, (16) dispense.class.php, (17) modificatif.class.php, (18) reference.class.php, and (19) utilisateur.class.php in obj/.

    Source:cr4wl3r
    Published:18 May 2010
    6.8
    Medium

    CVE-2010-1945

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in openMairie Openfoncier 2.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) action.class.php, (2) architecte.class.php, (3) avis.class.php, (4) bible.class.php, and (5) blocnote.class.php in obj/.

    Source:cr4wl3r
    Published:18 May 2010
    6.8
    Medium

    CVE-2010-1944

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in openMairie openCimetiere 2.01, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) autorisation.class.php, (2) courrierautorisation.class.php, (3) droit.class.php, (4) profil.class.php, (5) temp_defunt_sansemplacement.class.php, (6) utils.class.php, (7) cimetiere.class.php, (8) defunt.class.php, (9) emplacement.class.php, (10) tab_emplacement.class.php, (11) temp_emplacement.class.php, (12) voie.class.php, (13) collectivite.class.php, (14) defunttransfert.class.php, (15) entreprise.class.php, (16) temp_autorisation.class.php, (17) travaux.class.php, (18) zone.class.php, (19) courrier.class.php, (20) dossier.class.php, (21) plans.class.php, (22) temp_defunt.class.php, and (23) utilisateur.class.php in obj/.

    Source:cr4wl3r
    Published:18 May 2010
    7.6
    High

    CVE-2010-1939

    Last Modified: 27 Oct 2016

    Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers improper handling of a deleted window object.

    Source:Alexey Sintsov
    Published:13 May 2010
    9.3
    Critical

    CVE-2010-1938

    Last Modified: 11 Apr 2025

    Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.

    Source:Maksymilian Arciemowicz
    Published:28 May 2010