6.8
    Medium

    CVE-2010-1475

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:19 Apr 2010
    6.8
    Medium

    CVE-2010-1474

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:19 Apr 2010
    6.8
    Medium

    CVE-2010-1473

    Last Modified: 15 Dec 2016

    Directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:19 Apr 2010
    7.5
    High

    CVE-2010-1472

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:19 Apr 2010
    7.5
    High

    CVE-2010-1471

    Last Modified: 15 Dec 2016

    Directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:19 Apr 2010
    7.5
    High

    CVE-2010-1470

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:19 Apr 2010
    6.8
    Medium

    CVE-2010-1469

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Ternaria Informatica JProject Manager (com_jprojectmanager) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:19 Apr 2010
    7.5
    High

    CVE-2010-1468

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the Multi-Venue Restaurant Menu Manager (aka MVRMM or com_mv_restaurantmenumanager) component 1.5.2 Stable Update 3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the mid parameter in a menu_display action to index.php.

    Source:Valentin
    Published:19 Apr 2010
    7.5
    High

    CVE-2010-1467

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in openUrgence Vaccin 1.03 allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) collectivite.class.php, (2) injection.class.php, (3) utilisateur.class.php, (4) droit.class.php, (5) laboratoire.class.php, (6) vaccin.class.php, (7) effetsecondaire.class.php, (8) medecin.class.php, (9) individu.class.php, and (10) profil.class.php in gen/obj/.

    Source:cr4wl3r
    Published:16 Apr 2010
    6.8
    Medium

    CVE-2010-1466

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in openUrgence Vaccin 1.03 allows remote attackers to read arbitrary files via the dsn[phptype] parameter.

    Source:cr4wl3r
    Published:16 Apr 2010
    9.3
    Critical

    CVE-2010-1465

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Trellian FTP client 3.01, including 3.1.3.1789, allows remote attackers to execute arbitrary code via a long PASV response.

    Source:zombiefx
    Published:16 Apr 2010
    5
    Medium

    CVE-2010-1461

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via the view parameter to index.php.

    Source:AntiSecurity
    Published:16 Apr 2010
    5
    Medium

    CVE-2010-1460

    Last Modified: 11 Apr 2025

    The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which allows remote attackers to cause a denial of service (management module reboot) via TCP packets with malformed application data.

    Source:Alexey Sintsov
    Published:16 Apr 2010
    6.8
    Medium

    CVE-2010-1458

    Last Modified: 3 Jan 2011

    Stack-based buffer overflow in Create and Extract Zips TweakFS Zip Utility 1.0 for Flight Simulator X (FSX) allows remote attackers to execute arbitrary code via a long filename in a ZIP archive.

    Source:corelanc0d3r
    Published:20 Apr 2010
    4.9
    Medium

    CVE-2010-1457

    Last Modified: 4 Jul 2014

    Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 allows local users to read arbitrary files via a (1) -c or (2) -a option, which prints file contents in an error message.

    Source:Dan Rosenberg
    Published:12 May 2010
    4.3
    Medium

    CVE-2010-1453

    Last Modified: 19 Jun 2014

    Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter.

    Source:garwga
    Published:7 May 2010
    7
    High

    CVE-2010-1437

    Last Modified: 27 Jun 2014

    Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.

    Source:Toshiyuki Okajima
    Published:23 Apr 2010
    7.5
    High

    CVE-2010-1431

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter.

    Source:Nahuel Grisolia
    Published:21 Apr 2010
    9.3
    Critical

    CVE-2010-1423

    Last Modified: 23 Mar 2017

    Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.

    Source:Metasploit
    Published:9 Apr 2010
    6.8
    Medium

    CVE-2010-1411

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file that triggers a heap-based buffer overflow.

    Published:14 Jun 2010
    7.5
    High

    CVE-2010-1372

    Last Modified: 8 Jun 2014

    SQL injection vulnerability in the HD FLV Player (com_hdflvplayer) component 1.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:kaMtiEz
    Published:13 Apr 2010
    7.5
    High

    CVE-2010-1369

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the email parameter.

    Source:Crux
    Published:13 Apr 2010
    7.5
    High

    CVE-2010-1368

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in GameScript (GS) 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action.

    Source:FormatXformat
    Published:13 Apr 2010
    7.5
    High

    CVE-2010-1366

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in admin/admin_login.php in Uiga Fan Club 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin_name and (2) admin_password parameters.

    Source:cr4wl3r
    Published:13 Apr 2010
    7.5
    High

    CVE-2010-1365

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Uiga Fan Club, as downloaded on 20100310, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action.

    Source:Easy Laster
    Published:13 Apr 2010
    7.5
    High

    CVE-2010-1364

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action. NOTE: some of these details are obtained from third party information.

    Source:41.w4r10r
    Published:13 Apr 2010
    7.5
    High

    CVE-2010-1363

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JProjects (com_j-projects) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the project parameter in a projects action to index.php.

    Source:Pyske
    Published:13 Apr 2010
    4.3
    Medium

    CVE-2010-1361

    Last Modified: 23 May 2014

    Cross-site scripting (XSS) vulnerability in shop/USER_ARTIKEL_HANDLING_AUFRUF.php in PHPepperShop 2.5 allows remote attackers to inject arbitrary web script or HTML via the darstellen parameter.

    Source:Crux
    Published:13 Apr 2010
    7.5
    High

    CVE-2010-1360

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in FAQEngine 4.24.00 allow remote attackers to execute arbitrary PHP code via a URL in the path_faqe parameter to (1) attachs.php, (2) backup.php, (3) badwords.php, (4) categories.php, (5) changepw.php, (6) colorchooser.php, (7) colorwheel.php, (8) dbfiles.php, (9) diraccess.php, (10) faq.php, (11) index.php, (12) kb.php, and (13) stats.php.

    Source:kaMtiEz
    Published:13 Apr 2010
    5
    Medium

    CVE-2010-1354

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:Angela Zhang
    Published:12 Apr 2010
    5
    Medium

    CVE-2010-1353

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.

    Source:Vrs-hCk
    Published:12 Apr 2010
    5
    Medium

    CVE-2010-1352

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:AntiSecurity
    Published:12 Apr 2010
    6.8
    Medium

    CVE-2010-1351

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Nodesforum 1.033 and 1.045, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _nodesforum_path_from_here_to_nodesforum_folder parameter to erase_user_data.php and the (2) _nodesforum_code_path parameter to pre_output.php. NOTE: some of these details are obtained from third party information.

    Source:ITSecTeam
    Published:12 Apr 2010
    7.5
    High

    CVE-2010-1350

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the JP Jobs (com_jp_jobs) component 1.4.1 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Source:v3n0m
    Published:12 Apr 2010
    10
    Critical

    CVE-2010-1349

    Last Modified: 11 Apr 2025

    Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a heap overflow.

    Source:Marcin Ressel
    Published:12 Apr 2010
    6.8
    Medium

    CVE-2010-1346

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in admin/login.php in Mini CMS RibaFS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the login parameter. NOTE: some of these details are obtained from third party information.

    Source:cr4wl3r
    Published:9 Apr 2010
    5
    Medium

    CVE-2010-1345

    Last Modified: 8 Nov 2010

    Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:ALTBTA
    Published:9 Apr 2010
    7.5
    High

    CVE-2010-1344

    Last Modified: 8 Nov 2010

    SQL injection vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the fid parameter in a detail action to index.php.

    Source:ALTBTA
    Published:9 Apr 2010
    7.5
    High

    CVE-2010-1343

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in photo.php in SiteX 0.7.4 beta allows remote attackers to execute arbitrary SQL commands via the albumid parameter.

    Source:Sc0rpi0n
    Published:9 Apr 2010
    6.8
    Medium

    CVE-2010-1342

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Direct News 4.10.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter to (1) admin/menu.php and (2) library/lib.menu.php; and the adminroot parameter to (3) admin/media/update_content.php and (4) library/class.backup.php. NOTE: some of these details are obtained from third party information.

    Source:mat
    Published:9 Apr 2010
    7.5
    High

    CVE-2010-1341

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbitrary SQL commands via the s_flaeche parameter.

    Source:Easy Laster
    Published:9 Apr 2010
    5
    Medium

    CVE-2010-1340

    Last Modified: 18 Jun 2014

    Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:Chip d3 bi0s
    Published:9 Apr 2010
    7.5
    High

    CVE-2010-1338

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to execute arbitrary SQL commands via the userid parameter in a modboard action.

    Source:Easy Laster
    Published:9 Apr 2010
    7.5
    High

    CVE-2010-1337

    Last Modified: 17 Jun 2014

    Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote attackers to execute arbitrary PHP code via a URL in the (1) include and (2) Configuration['LANGUAGE'] parameters.

    Source:eidelweiss
    Published:9 Apr 2010
    7.5
    High

    CVE-2010-1336

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in INVOhost 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) newlanguage parameters to site.php, (3) search parameter to manuals.php, and (4) unspecified vectors to faq.php. NOTE: some of these details are obtained from third party information.

    Source:Andrés Gómez
    Published:9 Apr 2010
    6.8
    Medium

    CVE-2010-1335

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOT parameter to (1) city.get/city.get.php, (2) city.get/index.php, (3) message2.send/message.send.php, (4) message.send/message.send.php, and (5) pages.add/pages.add.php in insky/modules/. NOTE: some of these details are obtained from third party information.

    Source:mat
    Published:9 Apr 2010
    7.5
    High

    CVE-2010-1327

    Last Modified: 1 Aug 2014

    Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.

    Source:Lucas Apa
    Published:6 Jul 2010
    4
    Medium

    CVE-2010-1320

    Last Modified: 24 Jun 2014

    Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a request associated with (1) renewal or (2) validation.

    Source:Joel Johnson
    Published:20 Apr 2010
    10
    Critical

    CVE-2010-1318

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified vectors.

    Source:ZSploit.com
    Published:20 Apr 2010
    5
    Medium

    CVE-2010-1316

    Last Modified: 29 Dec 2010

    Multiple stack-based buffer overflows in Tembria Server Monitor before 5.6.1 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted (1) GET, (2) PUT, or (3) HEAD request, as demonstrated by a malformed GET request containing a long PATH_INFO to index.asp.

    Source:Lincoln
    Published:14 Apr 2010