7.5
    High

    CVE-2010-1653

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:wishnusakti + inc0mp13te
    Published:30 Apr 2010
    5
    Medium

    CVE-2010-1652

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the HelpCenter module in Help Center Live (HCL) 2.0.6 and 2.1.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the file parameter to module.php. NOTE: some of these details are obtained from third party information.

    Source:41.w4r10r
    Published:30 Apr 2010
    2.1
    Low

    CVE-2010-1636

    Last Modified: 8 Jul 2014

    The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows local users to read sensitive information from a write-only file descriptor.

    Source:Dan Rosenberg
    Published:7 Jun 2010
    6
    Medium

    CVE-2010-1622

    Last Modified: 11 Apr 2025

    SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.

    Source:Meder Kydyraliev
    Published:17 Jun 2010
    6.8
    Medium

    CVE-2010-1611

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in AlegroCart 1.1 allows remote attackers to hijack the authentication of the administrator for requests that reset the administrator password via a POST to admin/ with an update action.

    Source:The.Morpheus
    Published:29 Apr 2010
    6.8
    Medium

    CVE-2010-1607

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in wmi.php in the Webmoney Web Merchant Interface (aka WMI or com_wmi) component 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

    Source:wishnusakti + inc0mp13te
    Published:29 Apr 2010
    4.3
    Medium

    CVE-2010-1606

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in NCT Jobs Portal Script allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) Keywords, (3) Tags, or (4) Desired City field.

    Source:Sid3^effects
    Published:29 Apr 2010
    6.8
    Medium

    CVE-2010-1604

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in admin_login.php in NCT Jobs Portal Script allow remote attackers to execute arbitrary SQL commands via the (1) user parameter (aka login field) and (2) passwd parameter (aka password field). NOTE: some of these details are obtained from third party information.

    Source:Sid3^effects
    Published:29 Apr 2010
    7.5
    High

    CVE-2010-1603

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the ZiMB Core (aka ZiMBCore or com_zimbcore) component 0.1 in the ZiMB Manager collection for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:29 Apr 2010
    7.5
    High

    CVE-2010-1602

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the ZiMB Comment (com_zimbcomment) component 0.8.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:29 Apr 2010
    5
    Medium

    CVE-2010-1601

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the JA Comment (com_jacomment) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.

    Source:AntiSecurity
    Published:29 Apr 2010
    7.5
    High

    CVE-2010-1600

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the Media Mall Factory (com_mediamall) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter to index.php.

    Source:AntiSecurity
    Published:29 Apr 2010
    7.5
    High

    CVE-2010-1599

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in loadorder.php in NKInFoWeb 2.5 and 5.2.2.0 allows remote attackers to execute arbitrary SQL commands via the id_sp parameter.

    Source:d4rk-h4ck3r
    Published:29 Apr 2010
    9.3
    Critical

    CVE-2010-1597

    Last Modified: 3 Jan 2011

    Stack-based buffer overflow in zgtips.dll in ZipGenius 6.3.1.2552 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing an entry with a long filename.

    Source:corelanc0d3r
    Published:29 Apr 2010
    7.2
    High

    CVE-2010-1591

    Last Modified: 11 Apr 2025

    Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, including 0x83003C07, which allows local users to gain privileges via crafted IOCTL requests to the (1) HookCont.sys, (2) HookNtos.sys, (3) HOOKREG.sys, or (4) HookSys.sys device driver; or the (5) RsNTGdi.sys kernel module, reachable through \Device\RSNTGDI.

    Source:Dlrow
    Published:28 Apr 2010
    5
    Medium

    CVE-2010-1587

    Last Modified: 25 Jun 2014

    The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.

    Source:Veerendra G.G
    Published:20 Apr 2010
    4.3
    Medium

    CVE-2010-1586

    Last Modified: 25 Jun 2014

    Open redirect vulnerability in red2301.html in HP System Management Homepage (SMH) 2.x.x.x allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the RedirectUrl parameter.

    Source:Aung Khant
    Published:28 Apr 2010
    7.5
    High

    CVE-2010-1583

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN) Framework 1.5, as used in TaskFreak! before 0.6.3, allows remote attackers to execute arbitrary SQL commands via the username field in a login action.

    Source:Justin C. Klein Keane
    Published:5 May 2010
    7.5
    High

    CVE-2010-1559

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a speakerpopup action to index.php. NOTE: some of these details are obtained from third party information.

    Source:SadHaCkEr
    Published:27 Apr 2010
    10
    Critical

    CVE-2010-1555

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid Hostname parameter.

    Source:Metasploit
    Published:13 May 2010
    10
    Critical

    CVE-2010-1554

    Last Modified: 24 Mar 2011

    Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid iCount parameter.

    Source:Metasploit
    Published:13 May 2010
    10
    Critical

    CVE-2010-1553

    Last Modified: 24 Mar 2011

    Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid MaxAge parameter.

    Source:Metasploit
    Published:13 May 2010
    10
    Critical

    CVE-2010-1552

    Last Modified: 24 Mar 2011

    Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the act and app parameters.

    Source:Metasploit
    Published:13 May 2010
    10
    Critical

    CVE-2010-1549

    Last Modified: 1 Jan 2018

    Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.

    Source:Metasploit
    Published:7 May 2010
    5
    Medium

    CVE-2010-1544

    Last Modified: 11 Apr 2025

    micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port 80.

    Source:ad0nis
    Published:26 Apr 2010
    5
    Medium

    CVE-2010-1540

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the task parameter. NOTE: some of these details are obtained from third party information.

    Source:DevilZ TM
    Published:26 Apr 2010
    7.5
    High

    CVE-2010-1538

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in print_raincheck.php in phpRAINCHECK 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:cr4wl3r
    Published:26 Apr 2010
    7.5
    High

    CVE-2010-1537

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in phpCDB 1.0 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_global parameter to (1) firstvisit.php, (2) newfolder.php, (3) showfolders.php, (4) newlang.php, (5) showinnerfolder.php, (6) writecode.php, and (7) showcode.php.

    Source:cr4wl3r
    Published:26 Apr 2010
    7.5
    High

    CVE-2010-1535

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:26 Apr 2010
    5
    Medium

    CVE-2010-1534

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:Vrs-hCk
    Published:26 Apr 2010
    7.5
    High

    CVE-2010-1533

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the TweetLA (com_tweetla) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:26 Apr 2010
    5
    Medium

    CVE-2010-1532

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the givesight PowerMail Pro (com_powermail) component 1.5.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:26 Apr 2010
    7.5
    High

    CVE-2010-1531

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.

    Source:NoGe
    Published:26 Apr 2010
    7.5
    High

    CVE-2010-1529

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the Freestyle FAQs Lite (com_fsf) component, possibly 1.3, for Joomla! allows remote attackers to execute arbitrary SQL commands via the faqid parameter in an faq action to index.php.

    Source:Chip d3 bi0s
    Published:26 Apr 2010
    6.8
    Medium

    CVE-2010-1528

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in include/template.php in Uiga Proxy, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.

    Source:ITSecTeam
    Published:26 Apr 2010
    9.3
    Critical

    CVE-2010-1527

    Last Modified: 1 Apr 2017

    Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a long call-back-url parameter in an op-client-interface-version action.

    Source:Trancer
    Published:23 Aug 2010
    7.5
    High

    CVE-2010-1499

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in genre_artists.php in MusicBox 3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Ctacok
    Published:23 Apr 2010
    7.5
    High

    CVE-2010-1498

    Last Modified: 5 Jul 2010

    Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) download.php and (2) view_file.php.

    Source:Valentin Hoebel
    Published:23 Apr 2010
    4.3
    Medium

    CVE-2010-1497

    Last Modified: 5 Jul 2010

    Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:Valentin Hoebel
    Published:23 Apr 2010
    7.5
    High

    CVE-2010-1496

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cardID parameter in a view action to index.php.

    Source:Valentin
    Published:23 Apr 2010
    7.5
    High

    CVE-2010-1495

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Matamko (com_matamko) component 1.01 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:23 Apr 2010
    5
    Medium

    CVE-2010-1494

    Last Modified: 19 Feb 2017

    Directory traversal vulnerability in the AWDwall (com_awdwall) component 1.5.4 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:23 Apr 2010
    7.5
    High

    CVE-2010-1493

    Last Modified: 19 Feb 2017

    SQL injection vulnerability in the AWDwall (com_awdwall) component before 1.5.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cbuser parameter in an awdwall action to index.php.

    Source:AntiSecurity
    Published:23 Apr 2010
    5
    Medium

    CVE-2010-1491

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:23 Apr 2010
    4.3
    Medium

    CVE-2010-1486

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in _invoice.asp in CactuShop before 6.155 allow remote attackers to inject arbitrary web script or HTML via the (1) billing address or (2) shipping address.

    Source:7Safe
    Published:22 Apr 2010
    7.5
    High

    CVE-2010-1480

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the module parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:Yarolinux
    Published:19 Apr 2010
    7.5
    High

    CVE-2010-1479

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter in a raw action to index.php.

    Source:Yarolinux
    Published:19 Apr 2010
    6.8
    Medium

    CVE-2010-1478

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:19 Apr 2010
    7.5
    High

    CVE-2010-1477

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a latest_sermons action to index.php.

    Source:SadHaCkEr
    Published:19 Apr 2010
    6.8
    Medium

    CVE-2010-1476

    Last Modified: 15 Dec 2016

    Directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the view parameter to index.php.

    Source:AntiSecurity
    Published:19 Apr 2010