6.8
    Medium

    CVE-2010-1342

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Direct News 4.10.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter to (1) admin/menu.php and (2) library/lib.menu.php; and the adminroot parameter to (3) admin/media/update_content.php and (4) library/class.backup.php. NOTE: some of these details are obtained from third party information.

    Source:mat
    Published:9 Apr 2010
    7.5
    High

    CVE-2010-1341

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbitrary SQL commands via the s_flaeche parameter.

    Source:Easy Laster
    Published:9 Apr 2010
    5
    Medium

    CVE-2010-1340

    Last Modified: 18 Jun 2014

    Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:Chip d3 bi0s
    Published:9 Apr 2010
    7.5
    High

    CVE-2010-1338

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to execute arbitrary SQL commands via the userid parameter in a modboard action.

    Source:Easy Laster
    Published:9 Apr 2010
    7.5
    High

    CVE-2010-1337

    Last Modified: 17 Jun 2014

    Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote attackers to execute arbitrary PHP code via a URL in the (1) include and (2) Configuration['LANGUAGE'] parameters.

    Source:eidelweiss
    Published:9 Apr 2010
    7.5
    High

    CVE-2010-1336

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in INVOhost 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) newlanguage parameters to site.php, (3) search parameter to manuals.php, and (4) unspecified vectors to faq.php. NOTE: some of these details are obtained from third party information.

    Source:Andrés Gómez
    Published:9 Apr 2010
    6.8
    Medium

    CVE-2010-1335

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOT parameter to (1) city.get/city.get.php, (2) city.get/index.php, (3) message2.send/message.send.php, (4) message.send/message.send.php, and (5) pages.add/pages.add.php in insky/modules/. NOTE: some of these details are obtained from third party information.

    Source:mat
    Published:9 Apr 2010
    7.5
    High

    CVE-2010-1327

    Last Modified: 1 Aug 2014

    Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.

    Source:Lucas Apa
    Published:6 Jul 2010
    4
    Medium

    CVE-2010-1320

    Last Modified: 24 Jun 2014

    Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a request associated with (1) renewal or (2) validation.

    Source:Joel Johnson
    Published:20 Apr 2010
    10
    Critical

    CVE-2010-1318

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified vectors.

    Source:ZSploit.com
    Published:20 Apr 2010
    5
    Medium

    CVE-2010-1316

    Last Modified: 29 Dec 2010

    Multiple stack-based buffer overflows in Tembria Server Monitor before 5.6.1 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted (1) GET, (2) PUT, or (3) HEAD request, as demonstrated by a malformed GET request containing a long PATH_INFO to index.asp.

    Source:Lincoln
    Published:14 Apr 2010
    5
    Medium

    CVE-2010-1315

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:Chip d3 bi0s
    Published:8 Apr 2010
    5
    Medium

    CVE-2010-1314

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Highslide JS (com_hsconfig) component 1.5 and 2.0.9 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:AntiSecurity
    Published:8 Apr 2010
    4.3
    Medium

    CVE-2010-1313

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0.12 and 1.0.0.13 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:AntiSecurity
    Published:8 Apr 2010
    5
    Medium

    CVE-2010-1312

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:8 Apr 2010
    5
    Medium

    CVE-2010-1309

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary files via a .. (dot dot) in the w parameter to index.php.

    Source:eidelweiss
    Published:8 Apr 2010
    5
    Medium

    CVE-2010-1308

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:Vrs-hCk
    Published:8 Apr 2010
    5
    Medium

    CVE-2010-1307

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:Vrs-hCk
    Published:8 Apr 2010
    7.5
    High

    CVE-2010-1306

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:Vrs-hCk
    Published:8 Apr 2010
    5
    Medium

    CVE-2010-1305

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in jinventory.php in the JInventory (com_jinventory) component 1.23.02 and possibly other versions before 1.26.03, a module for Joomla!, allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:Chip d3 bi0s
    Published:8 Apr 2010
    5
    Medium

    CVE-2010-1304

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:Chip d3 bi0s
    Published:8 Apr 2010
    5
    Medium

    CVE-2010-1302

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

    Source:Chip d3 bi0s
    Published:7 Apr 2010
    7.5
    High

    CVE-2010-1301

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via the host_id parameter.

    Source:Jonathan Salwan
    Published:7 Apr 2010
    7.5
    High

    CVE-2010-1300

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbitrary SQL commands via the calbums parameter.

    Source:anT!-Tr0J4n
    Published:7 Apr 2010
    5.1
    Medium

    CVE-2010-1299

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) DefineRootToTool parameter to counter.php, (2) PathToRoot parameter to plugins/DPGguestbook/guestbookaction.php and (3) get_popUpResource parameter to backendpopup/popup.php. NOTE: some of these details are obtained from third party information.

    Source:eidelweiss
    Published:7 Apr 2010
    7.8
    High

    CVE-2010-1297

    Last Modified: 3 Nov 2017

    Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.

    Source:anonymous
    Published:4 Jun 2010
    9.3
    Critical

    CVE-2010-1296

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) .ASL, (2) .ABR, or (3) .GRD file.

    Source:LiquidWorm
    Published:27 May 2010
    8.8
    High

    CVE-2010-1280

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file.

    Source:LiquidWorm
    Published:13 May 2010
    7.5
    High

    CVE-2010-1272

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in includes/tgpinc.php in Gnat-TGP 1.2.20 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.

    Source:cr4wl3r
    Published:6 Apr 2010
    7.5
    High

    CVE-2010-1271

    Last Modified: 20 Oct 2017

    SQL injection vulnerability in showplugs.php in smartplugs 1.3 allows remote attackers to execute arbitrary SQL commands via the domain parameter.

    Source:Easy Laster
    Published:6 Apr 2010
    7.5
    High

    CVE-2010-1270

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitrary SQL commands via the id_auk parameter.

    Source:Easy Laster
    Published:6 Apr 2010
    7.5
    High

    CVE-2010-1269

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in auktion.php in phpscripte24 Niedrig Gebote Pro Auktions System II allows remote attackers to execute arbitrary SQL commands via the id_auk parameter.

    Source:Easy Laster
    Published:6 Apr 2010
    6.8
    Medium

    CVE-2010-1268

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in justVisual CMS 2.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files directory traversal sequences in the p parameter. NOTE: some of these details are obtained from third party information.

    Source:eidelweiss
    Published:6 Apr 2010
    5
    Medium

    CVE-2010-1267

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the com parameter to (1) cContactus.php, (2) cGuestbook.php, and (3) cArticle.php.

    Source:cr4wl3r
    Published:6 Apr 2010
    7.5
    High

    CVE-2010-1266

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) template, (2) menu, (3) events, and (4) SITEROOT parameters to template/babyweb/index.php; the (5) modules and (6) copyright parameters to template/calm/footer.php; the (7) menu parameter to template/calm/top.php; and the (8) modules, (9) copyright, and (10) menu parameters to template/wm025/footer.php.

    Source:cr4wl3r
    Published:6 Apr 2010
    7.5
    High

    CVE-2010-1265

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Adam Corley dcsFlashGames (com_dcs_flashgames) allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

    Source:kaMtiEz
    Published:6 Apr 2010
    9.3
    Critical

    CVE-2010-1248

    Last Modified: 16 Sept 2010

    Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."

    Source:Abysssec
    Published:8 Jun 2010
    9.3
    Critical

    CVE-2010-1247

    Last Modified: 10 Sept 2010

    Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1249.

    Source:Abysssec
    Published:8 Jun 2010
    9.3
    Critical

    CVE-2010-1246

    Last Modified: 10 Sept 2010

    Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record, aka "Excel RTD Memory Corruption Vulnerability."

    Source:Abysssec
    Published:8 Jun 2010
    9.3
    Critical

    CVE-2010-1245

    Last Modified: 29 Sept 2010

    Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-0821.

    Source:Abysssec
    Published:8 Jun 2010
    9.3
    Critical

    CVE-2010-1240

    Last Modified: 10 Mar 2011

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.

    Source:Metasploit
    Published:5 Apr 2010
    9.3
    Critical

    CVE-2010-1239

    Last Modified: 22 Nov 2017

    Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and (2) execute arbitrary programs embedded in a PDF document via an unspecified "/Launch /Action" sequence, a related issue to CVE-2009-0836.

    Source:Didier Stevens
    Published:5 Apr 2010
    5
    Medium

    CVE-2010-1226

    Last Modified: 11 Apr 2025

    The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of service (Safari, Mail, or Springboard crash) via a crafted innerHTML property of a DIV element, related to a "malformed character" issue.

    Source:Chase Higgins
    Published:1 Apr 2010
    9.3
    Critical

    CVE-2010-1225

    Last Modified: 11 Apr 2025

    The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restrict access from the guest OS to memory locations in the VMM work area, which allows context-dependent attackers to bypass certain anti-exploitation protection mechanisms on the guest OS via crafted input to a vulnerable application. NOTE: the vendor reportedly found that only systems with an otherwise vulnerable application are affected, because "the memory areas accessible from the guest cannot be leveraged to achieve either remote code execution or elevation of privilege and ... no data from the host is exposed to the guest OS."

    Source:Core Security
    Published:1 Apr 2010
    6.8
    Medium

    CVE-2010-1219

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the JA News (com_janews) component 1.0 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:AtT4CKxT3rR0r1ST
    Published:30 Mar 2010
    4.3
    Medium

    CVE-2010-1217

    Last Modified: 1 Sept 2017

    Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE: the original researcher states that the affected product is JE Tooltip, not Form Creator; however, the exploit URL suggests that Form Creator is affected.

    Source:Chip d3 bi0s
    Published:30 Mar 2010
    6.8
    Medium

    CVE-2010-1216

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in templates/template.php in notsoPureEdit 1.4.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the content parameter. NOTE: some of these details are obtained from third party information.

    Source:cr4wl3r
    Published:30 Mar 2010
    9.3
    Critical

    CVE-2010-1214

    Last Modified: 19 Aug 2014

    Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements.

    Source:J23
    Published:20 Jul 2010
    9.8
    Critical

    CVE-2010-1205

    Last Modified: 20 Jul 2010

    Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

    Source:kripthor
    Published:25 Jun 2010
    9.3
    Critical

    CVE-2010-1199

    Last Modified: 30 Jul 2014

    Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.

    Source:Martin Barbella
    Published:22 Jun 2010