4.3
    Medium

    CVE-2010-1048

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in blog/index.php in Uiga Business Portal allows remote attackers to inject arbitrary web script or HTML via the textcomment parameter (aka the Comment Box) in a noentryid action. NOTE: some of these details are obtained from third party information.

    Source:Sioma Labs
    Published:22 Mar 2010
    7.5
    High

    CVE-2010-1047

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in MASA2EL Music City 1.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a singer action.

    Source:alnjm33
    Published:22 Mar 2010
    7.5
    High

    CVE-2010-1046

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in index.php in Rostermain 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) userid (username) and (2) password parameters.

    Source:cr4wl3r
    Published:22 Mar 2010
    7.5
    High

    CVE-2010-1045

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Productbook (com_productbook) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: some of these details are obtained from third party information.

    Source:snakespc
    Published:22 Mar 2010
    7.5
    High

    CVE-2010-1044

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpPort parameter.

    Source:Asheesh Anaconda
    Published:22 Mar 2010
    7.5
    High

    CVE-2010-1043

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in jaxCMS 1.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.

    Source:Hamza 'MizoZ' N.
    Published:22 Mar 2010
    4.3
    Medium

    CVE-2010-1042

    Last Modified: 31 Mar 2017

    Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .AVI file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ITSecTeam
    Published:22 Mar 2010
    10
    Critical

    CVE-2010-1039

    Last Modified: 18 Jul 2010

    Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.

    Source:Rodrigo Rubira Branco
    Published:20 May 2010
    9.3
    Critical

    CVE-2010-1033

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in a certain Tetradyne ActiveX control in HP Operations Manager 7.5, 8.10, and 8.16 might allow remote attackers to execute arbitrary code via a long string argument to the (1) LoadFile or (2) SaveFile method, related to srcvw32.dll and srcvw4.dll.

    Source:mr_me
    Published:21 Apr 2010
    5
    Medium

    CVE-2010-1029

    Last Modified: 11 Apr 2025

    Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a STYLE element composed of a large number of *> sequences.

    Source:t12
    Published:24 Feb 2010
    6.8
    Medium

    CVE-2010-1003

    Last Modified: 16 Jun 2014

    Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langname parameter.

    Source:7Safe
    Published:19 Mar 2010
    7.5
    High

    CVE-2010-0985

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:FL0RiX
    Published:16 Mar 2010
    5
    Medium

    CVE-2010-0984

    Last Modified: 11 Apr 2025

    Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for databases/acidcat_3.mdb.

    Source:LionTurk
    Published:16 Mar 2010
    6.8
    Medium

    CVE-2010-0983

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in include/mail.inc.php in Rezervi 3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root parameter, a different vector than CVE-2007-2156.

    Source:r00t.h4x0r
    Published:16 Mar 2010
    4.3
    Medium

    CVE-2010-0982

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:FL0RiX
    Published:16 Mar 2010
    7.5
    High

    CVE-2010-0981

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the TPJobs (com_tpjobs) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_c[] parameter in a resadvsearch action to index.php.

    Source:FL0RiX
    Published:16 Mar 2010
    7.5
    High

    CVE-2010-0980

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in player.php in Left 4 Dead (L4D) Stats 1.1 allows remote attackers to execute arbitrary SQL commands via the steamid parameter.

    Source:Sora
    Published:16 Mar 2010
    5
    Medium

    CVE-2010-0978

    Last Modified: 11 Apr 2025

    KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb.

    Source:LionTurk
    Published:16 Mar 2010
    7.5
    High

    CVE-2010-0976

    Last Modified: 11 Apr 2025

    Acidcat CMS 3.5.x does not prevent access to install.asp after installation finishes, which might allow remote attackers to restart the installation process and have unspecified other impact via requests to install.asp and other install_*.asp scripts. NOTE: the final installation screen states "Important: you must now delete all files beginning with 'install' from the root directory."

    Source:LionTurk
    Published:16 Mar 2010
    7.5
    High

    CVE-2010-0975

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in external.php in PHPCityPortal allows remote attackers to execute arbitrary PHP code via a URL in the url parameter.

    Source:R3d-D3V!L
    Published:16 Mar 2010
    7.5
    High

    CVE-2010-0974

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) video_show.php, (2) spotlight_detail.php, (3) real_estate_details.php, and (4) auto_details.php.

    Source:R3d-D3V!L
    Published:16 Mar 2010
    7.5
    High

    CVE-2010-0973

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in phppool media Domain Verkaus and Auktions Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Easy Laster
    Published:16 Mar 2010
    7.5
    High

    CVE-2010-0972

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

    Source:jdc
    Published:16 Mar 2010
    2.1
    Low

    CVE-2010-0971

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges, to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php, the (3) Type and (4) Title fields in tools/groups/create_manual.php, and the (5) Title field in assignments/add_assignment.php. NOTE: some of these details are obtained from third party information.

    Source:ITSecTeam
    Published:16 Mar 2010
    7.5
    High

    CVE-2010-0970

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in phpmylogon.php in PhpMyLogon 2 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

    Source:blake
    Published:16 Mar 2010
    7.5
    High

    CVE-2010-0968

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in bannershow.php in Geekhelps ADMP 1.01 allows remote attackers to execute arbitrary SQL commands via the click parameter.

    Source:ITSecTeam
    Published:16 Mar 2010
    5.1
    Medium

    CVE-2010-0967

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the style parameter to (1) colorvoid/footer.php, (2) default-green/footer.php, (3) default-orange/footer.php, and (4) default/footer.php in themes/. NOTE: some of these details are obtained from third party information.

    Source:ITSecTeam
    Published:16 Mar 2010
    6.8
    Medium

    CVE-2010-0966

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in inc/config.php in deV!L`z Clanportal (DZCP) 1.5.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the basePath parameter.

    Source:cr4wl3r
    Published:16 Mar 2010
    7.5
    High

    CVE-2010-0964

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in start.php in Eros Webkatalog allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik action.

    Source:Easy Laster
    Published:16 Mar 2010
    6.8
    Medium

    CVE-2010-0958

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in modules/hayoo/index.php in Tribisur 2.1, 2.0, and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via directory traversal sequences in the theme parameter. NOTE: some of these details are obtained from third party information.

    Source:cr4wl3r
    Published:9 Mar 2010
    7.5
    High

    CVE-2010-0955

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in index.php in Bild Flirt Community 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Easy Laster
    Published:9 Mar 2010
    6.8
    Medium

    CVE-2010-0953

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in mod.php in phpCOIN 1.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter.

    Source:_mlk_
    Published:9 Mar 2010
    6.8
    Medium

    CVE-2010-0952

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in OneCMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an elite action.

    Source:Ctacok & .:[melkiy]:
    Published:9 Mar 2010
    7.5
    High

    CVE-2010-0951

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in go_target.php in dev4u CMS allows remote attackers to execute arbitrary SQL commands via the kontent_id parameter.

    Source:Easy Laster
    Published:9 Mar 2010
    6.8
    Medium

    CVE-2010-0948

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in profil.php in Bigforum 4.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Ctacok
    Published:9 Mar 2010
    7.5
    High

    CVE-2010-0946

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Keep It Simple Stupid (KISS) Software Advertiser (com_ksadvertiser) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showcats action to index.php.

    Source:FL0RiX
    Published:8 Mar 2010
    7.5
    High

    CVE-2010-0945

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the HotBrackets Tournament Brackets (com_hotbrackets) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:FL0RiX
    Published:8 Mar 2010
    5
    Medium

    CVE-2010-0944

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:FL0RiX
    Published:8 Mar 2010
    5
    Medium

    CVE-2010-0943

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the JA Showcase (com_jashowcase) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a jashowcase action to index.php.

    Source:FL0RiX
    Published:8 Mar 2010
    5
    Medium

    CVE-2010-0942

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:FL0RiX
    Published:8 Mar 2010
    5
    Medium

    CVE-2010-0939

    Last Modified: 11 Apr 2025

    Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for fpdb/abb.mdb.

    Source:ViRuSMaN
    Published:8 Mar 2010
    4.3
    Medium

    CVE-2010-0936

    Last Modified: 22 May 2014

    Cross-site scripting (XSS) vulnerability in auth.asp on the D-LINK DKVM-IP8 with firmware 2282_dlinkA4_p8_20071213 allows remote attackers to inject arbitrary web script or HTML via the nickname parameter.

    Source:POPCORN
    Published:8 Mar 2010
    3.5
    Low

    CVE-2010-0926

    Last Modified: 1 Jun 2014

    The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.

    Source:kingcope
    Published:5 Feb 2010
    6.2
    Medium

    CVE-2010-0916

    Last Modified: 11 Aug 2014

    Unspecified vulnerability in Oracle OpenSolaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to rdist.

    Source:Monarch Rich
    Published:13 Jul 2010
    5
    Medium

    CVE-2010-0904

    Last Modified: 20 Aug 2011

    Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect integrity via unknown vectors.

    Source:Metasploit
    Published:13 Jul 2010
    10
    Critical

    CVE-2010-0886

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Source:Ruben Santamarta
    Published:9 Apr 2010
    7.5
    High

    CVE-2010-0842

    Last Modified: 16 Feb 2012

    Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an uncontrolled array index that allows remote attackers to execute arbitrary code via a MIDI file with a crafted MixerSequencer object, related to the GM_Song structure.

    Source:Metasploit
    Published:30 Mar 2010
    9.8
    Critical

    CVE-2010-0840

    Last Modified: 6 Mar 2011

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."

    Source:Metasploit
    Published:30 Mar 2010
    7.5
    High

    CVE-2010-0838

    Last Modified: 20 Sept 2010

    Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a stack-based buffer overflow using an untrusted size value in the readMabCurveData function in the CMM module in the JVM.

    Source:Abysssec
    Published:30 Mar 2010
    6.9
    Medium

    CVE-2010-0832

    Last Modified: 10 Jul 2010

    pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before 1.1.1-2ubuntu5 in PAM on Ubuntu 10.04 LTS allows local users to change the ownership of arbitrary files via a symlink attack on .cache in a user's home directory, related to "user file stamps" and the motd.legal-notice file.

    Source:Kristian Erik Hermansen
    Published:12 Jul 2010