9.3
    Critical

    CVE-2010-1175

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vulnerability."

    Source:krafty
    Published:29 Mar 2010
    5
    Medium

    CVE-2010-1174

    Last Modified: 4 Sept 2010

    Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RRQ) or (2) write (aka WRQ) request, or other TFTP packet. NOTE: some of these details are obtained from third party information.

    Source:_SuBz3r0_
    Published:29 Mar 2010
    7.1
    High

    CVE-2010-1173

    Last Modified: 9 Aug 2010

    The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel 2.6.33.3 and earlier, when SCTP is enabled, allows remote attackers to cause a denial of service (system crash) via an SCTPChunkInit packet containing multiple invalid parameters that require a large amount of error data.

    Source:Jon Oberheide
    Published:29 Apr 2010
    6.8
    Medium

    CVE-2010-1159

    Last Modified: 16 Nov 2017

    Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) large length value in an EAPOL packet or (2) long EAPOL packet.

    Source:Lukas Lueg
    Published:28 Oct 2013
    2.6
    Low

    CVE-2010-1157

    Last Modified: 11 Apr 2025

    Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.

    Source:Deniz Cevik
    Published:21 Apr 2010
    5
    Medium

    CVE-2010-1152

    Last Modified: 24 Jun 2014

    memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a long line that triggers excessive memory allocation. NOTE: some of these details are obtained from third party information.

    Source:fallenpegasus
    Published:27 Oct 2009
    6
    Medium

    CVE-2010-1147

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Open Direct Connect Hub (aka Open DC Hub or OpenDCHub) 0.8.1 allows remote authenticated users to execute arbitrary code via a long MyINFO message.

    Source:Pierre Nogues
    Published:31 Mar 2010
    6.9
    Medium

    CVE-2010-1146

    Last Modified: 30 Jan 2017

    The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the .reiserfs_priv directory, which allows local users to gain privileges by modifying (1) extended attributes or (2) ACLs, as demonstrated by deleting a file under .reiserfs_priv/xattrs/.

    Source:Jon Oberheide
    Published:12 Apr 2010
    4.3
    Medium

    CVE-2010-1143

    Last Modified: 1 Jul 2014

    Cross-site scripting (XSS) vulnerability in VMware View (formerly Virtual Desktop Manager or VDM) 3.1.x before 3.1.3 build 252693 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:Alexey Sintsov
    Published:7 May 2010
    9.3
    Critical

    CVE-2010-1132

    Last Modified: 5 Dec 2016

    The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.

    Source:kingcope
    Published:7 Mar 2010
    4.3
    Medium

    CVE-2010-1131

    Last Modified: 11 Apr 2025

    JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to cause a denial of service (application crash) via an HTML document composed of many successive occurrences of the <object> substring.

    Source:Mathias Karlsson
    Published:26 Mar 2010
    5
    Medium

    CVE-2010-1130

    Last Modified: 3 Jun 2014

    session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a .. (dot dot).

    Source:Grzegorz Stachowiak
    Published:25 Feb 2010
    6.4
    Medium

    CVE-2010-1128

    Last Modified: 12 Jun 2014

    The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

    Source:Rasmus
    Published:25 Feb 2010
    10
    Critical

    CVE-2010-1119

    Last Modified: 21 Dec 2016

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo and Ralf Philipp Weinmann during a Pwn2Own competition at CanSecWest 2010.

    Source:MJ Keith
    Published:25 Mar 2010
    7.5
    High

    CVE-2010-1114

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pg parameter to index.php and the (2) path parameter to news/form.php.

    Source:indoushka
    Published:25 Mar 2010
    4.3
    Medium

    CVE-2010-1113

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to index.php.

    Source:indoushka
    Published:25 Mar 2010
    4.3
    Medium

    CVE-2010-1112

    Last Modified: 3 Jul 2014

    Cross-site scripting (XSS) vulnerability in cat.php in KloNews 2.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Source:cr4wl3r
    Published:25 Mar 2010
    4.3
    Medium

    CVE-2010-1111

    Last Modified: 9 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Jokes Complete Website allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to joke.php and the (2) searchingred parameter to results.php.

    Source:indoushka
    Published:25 Mar 2010
    6.8
    Medium

    CVE-2010-1109

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in index.php in phpMySport 1.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) v2 parameter in a member view action, (2) v1 parameter in a news action, (3) v1 parameter in an information action, (4) v2 parameter in a team view action, (5) v2 parameter in a club view action, or (6) v2 parameter in a matches view action.

    Source:XaDoS
    Published:25 Mar 2010
    7.5
    High

    CVE-2010-1106

    Last Modified: 2 Oct 2014

    PHP remote file inclusion vulnerability in cgi/index.php in AdvertisementManager 3.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the req parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.

    Source:indoushka
    Published:25 Mar 2010
    4.3
    Medium

    CVE-2010-1095

    Last Modified: 8 Jun 2014

    Cross-site scripting (XSS) vulnerability in login_reset_password_page.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:snakespc
    Published:24 Mar 2010
    7.5
    High

    CVE-2010-1094

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in news.php in DZ EROTIK Auktionshaus V4rgo allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Easy Laster
    Published:24 Mar 2010
    6.8
    Medium

    CVE-2010-1093

    Last Modified: 2 Oct 2010

    SQL injection vulnerability in rss.php in 1024 CMS 2.1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a vp action.

    Source:Stephan Sattler
    Published:24 Mar 2010
    7.5
    High

    CVE-2010-1092

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in login.php in ScriptsFeed Business Directory Software allow remote attackers to execute arbitrary SQL commands via the (1) us and (2) ps parameters.

    Source:Crux
    Published:24 Mar 2010
    4.3
    Medium

    CVE-2010-1091

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in contact.php in phpMySite allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) city, (3) email, (4) state, and (5) message parameters.

    Source:Crux
    Published:24 Mar 2010
    7.5
    High

    CVE-2010-1090

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in phpMySite allows remote attackers to execute arbitrary SQL commands via the action parameter.

    Source:Crux
    Published:24 Mar 2010
    7.5
    High

    CVE-2010-1089

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in vedi_faq.php in PHP Trouble Ticket 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:kaMtiEz
    Published:24 Mar 2010
    5
    Medium

    CVE-2010-1081

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:kaMtiEz
    Published:23 Mar 2010
    7.5
    High

    CVE-2010-1078

    Last Modified: 7 Jun 2014

    SQL injection vulnerability in archive.php in XlentProjects SphereCMS 1.1 alpha allows remote attackers to execute arbitrary SQL commands via encoded null bytes ("%00") in the view parameter, which bypasses a protection mechanism.

    Source:AmnPardaz Security Research Team
    Published:23 Mar 2010
    6.8
    Medium

    CVE-2010-1077

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the vbseourl parameter.

    Source:ViRuSMaN
    Published:23 Mar 2010
    7.5
    High

    CVE-2010-1073

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the jEmbed-Embed Anything (com_jembed) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a summary action to index.php.

    Source:FL0RiX
    Published:23 Mar 2010
    7.5
    High

    CVE-2010-1071

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in profil.php in phpMDJ 1.0.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:k4cp3r & Ablus
    Published:23 Mar 2010
    7.5
    High

    CVE-2010-1070

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in ImagoScripts Deviant Art Clone allows remote attackers to execute arbitrary SQL commands via the seid parameter in a forums viewcat action.

    Source:alnjm33
    Published:23 Mar 2010
    7.5
    High

    CVE-2010-1069

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in games/game.php in ProArcadeScript allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Err0R
    Published:23 Mar 2010
    5
    Medium

    CVE-2010-1067

    Last Modified: 11 Apr 2025

    E-membres 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/bdEMembres.mdb.

    Source:ViRuSMaN
    Published:23 Mar 2010
    5
    Medium

    CVE-2010-1066

    Last Modified: 11 Apr 2025

    AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for control/db_backup.php.

    Source:alnjm33
    Published:23 Mar 2010
    5
    Medium

    CVE-2010-1065

    Last Modified: 11 Apr 2025

    Lebisoft Ziyaretci Defteri 7.4 and 7.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/lebisoft.mdb.

    Source:indoushka
    Published:23 Mar 2010
    5
    Medium

    CVE-2010-1064

    Last Modified: 11 Apr 2025

    Erolife AjxGaleri VT stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/ajxgaleri.mdb.

    Source:LionTurk
    Published:23 Mar 2010
    6.8
    Medium

    CVE-2010-1062

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter. NOTE: some of these details are obtained from third party information.

    Source:Pouya Daneshmand
    Published:23 Mar 2010
    6.8
    Medium

    CVE-2010-1060

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter.

    Source:Pouya Daneshmand
    Published:23 Mar 2010
    6.8
    Medium

    CVE-2010-1058

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter.

    Source:Pouya Daneshmand
    Published:23 Mar 2010
    6.8
    Medium

    CVE-2010-1057

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in Phpkobo AdFreely (aka Ad Board Script) 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a ..// (dot dot slash slash) in the LANG_CODE parameter to common.inc.php in (1) codelib/cfg/, (2) codelib/sys/, (3) staff/, and (4) staff/app/; and (5) staff/file.php. NOTE: some of these details are obtained from third party information.

    Source:ITSecTeam
    Published:23 Mar 2010
    6.8
    Medium

    CVE-2010-1056

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

    Source:AtT4CKxT3rR0r1ST
    Published:23 Mar 2010
    5.1
    Medium

    CVE-2010-1055

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in osDate 2.1.9 and 2.5.4, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the config[forum_installed] parameter to (1) forum/adminLogin.php and (2) forum/userLogin.php. NOTE: some of these details are obtained from third party information.

    Source:NoGe
    Published:23 Mar 2010
    7.5
    High

    CVE-2010-1054

    Last Modified: 15 Jun 2014

    Multiple SQL injection vulnerabilities in ParsCMS allow remote attackers to execute arbitrary SQL commands via the RP parameter to (1) fa_default.asp and (2) en_default.asp.

    Source:Isfahan
    Published:23 Mar 2010
    6.8
    Medium

    CVE-2010-1053

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to (a) userlogin.php and (b) managerlogin.php. NOTE: some of these details are obtained from third party information.

    Source:cr4wl3r
    Published:22 Mar 2010
    4.3
    Medium

    CVE-2010-1052

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) mday parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:kaMtiEz
    Published:22 Mar 2010
    7.5
    High

    CVE-2010-1051

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) month parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:kaMtiEz
    Published:22 Mar 2010
    7.5
    High

    CVE-2010-1050

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in AudiStat 1.3 allows remote attackers to execute arbitrary SQL commands via the mday parameter.

    Source:kaMtiEz
    Published:22 Mar 2010
    7.5
    High

    CVE-2010-1049

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Uiga Business Portal allow remote attackers to execute arbitrary SQL commands via the (1) noentryid parameter to blog/index.php and the (2) p parameter to index2.php.

    Source:Sioma Labs
    Published:22 Mar 2010