4.3
    Medium

    CVE-2010-1746

    Last Modified: 7 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in the Table JX (com_grid) component for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) data_search and (2) rpp parameters to index.php.

    Source:Valentin
    Published:6 May 2010
    7.5
    High

    CVE-2010-1744

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in product.html in B2B Gold Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:v3n0m
    Published:6 May 2010
    7.5
    High

    CVE-2010-1743

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in projects.php in Scratcher allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:cr4wl3r
    Published:6 May 2010
    4.3
    Medium

    CVE-2010-1742

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in projects.php in Scratcher allows remote attackers to inject arbitrary web script or HTML via the show parameter.

    Source:cr4wl3r
    Published:6 May 2010
    7.5
    High

    CVE-2010-1741

    Last Modified: 29 Jun 2014

    SQL injection vulnerability in request_account.php in Billwerx RC 5.2.2 PL2 allows remote attackers to execute arbitrary SQL commands via the primary_number parameter.

    Source:indoushka
    Published:6 May 2010
    7.5
    High

    CVE-2010-1740

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands via the lng parameter.

    Source:indoushka
    Published:6 May 2010
    7.5
    High

    CVE-2010-1739

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the feedid parameter in a categories action to index.php.

    Source:Archimonde
    Published:6 May 2010
    6.8
    Medium

    CVE-2010-1737

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in core/includes/gfw_smarty.php in Gallo 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[gfwroot] parameter.

    Source:cr4wl3r
    Published:6 May 2010
    4.9
    Medium

    CVE-2010-1735

    Last Modified: 11 Apr 2025

    The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.

    Source:MJ0011
    Published:5 May 2010
    4.9
    Medium

    CVE-2010-1734

    Last Modified: 11 Apr 2025

    The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.

    Source:MJ0011
    Published:5 May 2010
    7.5
    High

    CVE-2010-1727

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in type.asp in JobPost 1.0 allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: some of these details are obtained from third party information.

    Source:Sid3^effects
    Published:5 May 2010
    7.5
    High

    CVE-2010-1726

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in offers_buy.php in EC21 Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:v3n0m
    Published:5 May 2010
    7.5
    High

    CVE-2010-1725

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:v3n0m
    Published:5 May 2010
    4.3
    Medium

    CVE-2010-1724

    Last Modified: 27 Jun 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to index.php, which is not properly handled by ZLanguage.php.

    Source:High-Tech Bridge SA
    Published:5 May 2010
    6.8
    Medium

    CVE-2010-1723

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:4 May 2010
    6.8
    Medium

    CVE-2010-1722

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:4 May 2010
    7.5
    High

    CVE-2010-1721

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the Intellectual Property (aka IProperty or com_iproperty) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an agentproperties action to index.php.

    Source:v3n0m
    Published:4 May 2010
    7.5
    High

    CVE-2010-1720

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the katid parameter in a qpListele action to index.php.

    Source:Valentin Hoebel
    Published:4 May 2010
    6.8
    Medium

    CVE-2010-1719

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:4 May 2010
    6.8
    Medium

    CVE-2010-1718

    Last Modified: 15 Dec 2016

    Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

    Source:wishnusakti + inc0mp13te
    Published:4 May 2010
    7.5
    High

    CVE-2010-1717

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:4 May 2010
    7.5
    High

    CVE-2010-1716

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in the Agenda Address Book (com_agenda) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Source:v3n0m
    Published:4 May 2010
    6.8
    Medium

    CVE-2010-1715

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:AntiSecurity
    Published:4 May 2010
    5
    Medium

    CVE-2010-1714

    Last Modified: 15 Dec 2016

    Directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:4 May 2010
    7.5
    High

    CVE-2010-1713

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter in a News article modload action.

    Source:BILGE_KAGAN
    Published:4 May 2010
    4.3
    Medium

    CVE-2010-1712

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in base/Comments.php in Webmobo WB News 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and possibly (2) message parameters. NOTE: some of these details are obtained from third party information.

    Source:ITSecTeam
    Published:4 May 2010
    4.3
    Medium

    CVE-2010-1711

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the usuario parameter.

    Source:JosS
    Published:4 May 2010
    6.8
    Medium

    CVE-2010-1710

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the idioma parameter.

    Source:JosS
    Published:4 May 2010
    7.5
    High

    CVE-2010-1708

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in agentadmin.php in Free Realty allow remote attackers to execute arbitrary SQL commands via the (1) login field (aka agentname parameter) or (2) password field (aka agentpassword parameter).

    Source:Sid3^effects
    Published:4 May 2010
    7.5
    High

    CVE-2010-1706

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in login.php in 2daybiz Auction Script allow remote attackers to execute arbitrary SQL commands via (1) the login field (aka the username parameter), and possibly (2) the password field, to index.php. NOTE: some of these details are obtained from third party information.

    Source:Sid3^effects
    Published:4 May 2010
    7.5
    High

    CVE-2010-1705

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in casting_view.php in Modelbook allows remote attackers to execute arbitrary SQL commands via the adnum parameter.

    Source:v3n0m
    Published:4 May 2010
    7.5
    High

    CVE-2010-1704

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to execute arbitrary SQL commands via (1) the password field to login.php, (2) the login field (aka email parameter) to login.php, (3) the password field (aka pass parameter) to the default URI under admin/, and possibly (4) the login field to the default URI under admin/. NOTE: some of these details are obtained from third party information.

    Source:Sid3^effects
    Published:4 May 2010
    4.3
    Medium

    CVE-2010-1703

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field.

    Source:Sid3^effects
    Published:4 May 2010
    7.5
    High

    CVE-2010-1702

    Last Modified: 24 Jan 2017

    SQL injection vulnerability in submitticket.php in WHMCompleteSolution (WHMCS) 4.2 allows remote attackers to execute arbitrary SQL commands via the deptid parameter.

    Source:Islam DefenDers
    Published:4 May 2010
    7.5
    High

    CVE-2010-1701

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in browse.html in PHP Video Battle Script allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:v3n0m
    Published:4 May 2010
    9.3
    Critical

    CVE-2010-1688

    Last Modified: 15 Nov 2017

    Stack-based buffer overflow in 2BrightSparks SyncBack Freeware 3.2.20.0, and possibly other versions before 3.2.21, allows user-assisted remote attackers to execute arbitrary code via a long filename in a (1) .sps or (2) zip profile.

    Source:Lincoln
    Published:24 May 2010
    5
    Medium

    CVE-2010-1687

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in lpd.exe in Mocha W32 LPD 1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted "recieve jobs" request. NOTE: some of these details are obtained from third party information.

    Source:mr_me
    Published:4 May 2010
    9.3
    Critical

    CVE-2010-1686

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in (1) Urgent Backup 3.20, and (2) ABC Backup Pro 5.20 and ABC Backup 5.50, allows user-assisted remote attackers to execute arbitrary code via a crafted ZIP archive.

    Source:Lincoln
    Published:4 May 2010
    9.3
    Critical

    CVE-2010-1685

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in CursorArts ZipWrangler 1.20 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename.

    Source:TecR0c & Sud0
    Published:4 May 2010
    7.6
    High

    CVE-2010-1681

    Last Modified: 26 Jun 2011

    Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256.

    Source:Metasploit
    Published:5 May 2010
    5
    Medium

    CVE-2010-1677

    Last Modified: 6 Dec 2014

    MHonArc 2.6.16 allows remote attackers to cause a denial of service (CPU consumption) via start tags that are placed within other start tags, as demonstrated by a <bo<bo<bo<bo<body>dy>dy>dy>dy> sequence, a different vulnerability than CVE-2010-4524.

    Source:anonymous
    Published:3 Jan 2011
    10
    Critical

    CVE-2010-1663

    Last Modified: 11 Apr 2025

    The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Source:Jordi Chancel
    Published:30 Apr 2010
    4.3
    Medium

    CVE-2010-1662

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in acpmoderate.php in PHP-Quick-Arcade (PHPQA) 3.0.21 allows remote attackers to inject arbitrary web script or HTML via the serv parameter.

    Source:ITSecTeam
    Published:30 Apr 2010
    7.5
    High

    CVE-2010-1661

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in PHP-Quick-Arcade (PHPQA) 3.0.21 allow remote attackers to execute arbitrary SQL commands via the (1) phpqa_user_c parameter to Arcade.php and the (2) id parameter to acpmoderate.php.

    Source:ITSecTeam
    Published:30 Apr 2010
    7.5
    High

    CVE-2010-1660

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in help-details.php in CLScript Classifieds Script allows remote attackers to execute arbitrary SQL commands via the hpId parameter.

    Source:41.w4r10
    Published:30 Apr 2010
    5
    Medium

    CVE-2010-1659

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:30 Apr 2010
    5
    Medium

    CVE-2010-1658

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:30 Apr 2010
    5
    Medium

    CVE-2010-1657

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:30 Apr 2010
    7.5
    High

    CVE-2010-1656

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in the Airiny ABC (com_abc) component 1.1.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sectionid parameter in an abc action to index.php.

    Source:AntiSecurity
    Published:30 Apr 2010
    7.5
    High

    CVE-2010-1654

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in system_member_login.php in Infocus Real Estate Enterprise Edition allow remote attackers to execute arbitrary SQL commands via the (1) username (aka login) and (2) password parameters. NOTE: some of these details are obtained from third party information.

    Source:Sid3^effects
    Published:30 Apr 2010