7.5
    High

    CVE-2010-0698

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in backoffice/login.asp in Dynamicsoft WSC CMS 2.2 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: some of these details are obtained from third party information.

    Source:Phenom
    Published:23 Feb 2010
    5
    Medium

    CVE-2010-0696

    Last Modified: 3 Nov 2016

    Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../.../ (modified dot dot) in the file parameter.

    Source:Pouya Daneshmand
    Published:23 Feb 2010
    4.3
    Medium

    CVE-2010-0695

    Last Modified: 6 Jan 2017

    Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id parameter.

    Source:Red-D3v1L
    Published:23 Feb 2010
    7.5
    High

    CVE-2010-0694

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the PerchaGallery (com_perchagallery) component before 1.5b for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an editunidad action to index.php.

    Source:FL0RiX
    Published:23 Feb 2010
    7.5
    High

    CVE-2010-0693

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:JaMbA
    Published:23 Feb 2010
    7.5
    High

    CVE-2010-0691

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands via the s parameter.

    Source:Lo$T
    Published:23 Feb 2010
    7.5
    High

    CVE-2010-0690

    Last Modified: 12 Nov 2010

    SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbitrary SQL commands via the pfid parameter in a catalog action.

    Source:JaMbA
    Published:23 Feb 2010
    9.3
    Critical

    CVE-2010-0688

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a crafted (1) .orb or (2) .ov file.

    Source:Metasploit
    Published:19 Mar 2010
    4
    Medium

    CVE-2010-0682

    Last Modified: 4 May 2017

    WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

    Source:tmacuk
    Published:23 Feb 2010
    5
    Medium

    CVE-2010-0681

    Last Modified: 11 Apr 2025

    ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for admin/backup.sql.

    Source:ViRuSMaN
    Published:22 Feb 2010
    7.5
    High

    CVE-2010-0680

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in ZeusCMS 0.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.

    Source:ViRuSMaN
    Published:22 Feb 2010
    9.3
    Critical

    CVE-2010-0679

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos ChemView 1.9.5.1 allow remote attackers to execute arbitrary code via a large number of white space characters in the filename argument to the (1) SaveasMolFile and (2) ReadMolFile methods.

    Source:Metasploit
    Published:22 Feb 2010
    6.8
    Medium

    CVE-2010-0678

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the includes_directory parameter.

    Source:kaMtiEz
    Published:22 Feb 2010
    7.5
    High

    CVE-2010-0677

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the get parameter.

    Source:kaMtiEz
    Published:22 Feb 2010
    4.3
    Medium

    CVE-2010-0675

    Last Modified: 6 Jun 2014

    Cross-site scripting (XSS) vulnerability in index.php in BGSvetionik BGS CMS 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action. NOTE: some of these details are obtained from third party information.

    Published:22 Feb 2010
    5
    Medium

    CVE-2010-0674

    Last Modified: 11 Apr 2025

    StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for path/stats.mdb.

    Source:Phenom
    Published:22 Feb 2010
    7.5
    High

    CVE-2010-0673

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress allows remote attackers to execute arbitrary SQL commands via the postid parameter.

    Source:kaMtiEz
    Published:22 Feb 2010
    7.5
    High

    CVE-2010-0672

    Last Modified: 12 Jan 2017

    SQL injection vulnerability in index.php in WSN Guest 1.02 allows remote attackers to execute arbitrary SQL commands via the orderlinks parameter.

    Source:Gamoscu
    Published:22 Feb 2010
    7.5
    High

    CVE-2010-0671

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in KR MEDIA Pogodny CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a niusy action.

    Source:Ariko-Security
    Published:22 Feb 2010
    5
    Medium

    CVE-2010-0665

    Last Modified: 11 Apr 2025

    JAG (Just Another Guestbook) 1.14 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for jag/database.sql.

    Source:Phenom
    Published:19 Feb 2010
    9.3
    Critical

    CVE-2010-0655

    Last Modified: 7 Jun 2014

    Use-after-free vulnerability in Google Chrome before 4.0.249.78 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving the display of a blocked popup window during navigation to a different web site.

    Source:Cesar Cerrudo
    Published:18 Feb 2010
    5
    Medium

    CVE-2010-0642

    Last Modified: 11 Apr 2025

    Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded characters in the filename extension, as demonstrated by (1) changing .jhtml to %2Ejhtml, (2) changing .jhtml to .jhtm%6C, (3) appending %00 after .jhtml, and (4) appending %c0%80 after .jhtml, related to the (a) doc/docindex.jhtml, (b) browserId/wizardForm.jhtml, (c) webline/html/forms/callback.jhtml, (d) webline/html/forms/callbackICM.jhtml, (e) webline/html/agent/AgentFrame.jhtml, (f) webline/html/agent/default/badlogin.jhtml, (g) callme/callForm.jhtml, (h) webline/html/multichatui/nowDefunctWindow.jhtml, (i) browserId/wizard.jhtml, (j) admin/CiscoAdmin.jhtml, (k) msccallme/mscCallForm.jhtml, and (l) webline/html/admin/wcs/LoginPage.jhtml components.

    Source:s4squatch
    Published:17 Feb 2010
    4.3
    Medium

    CVE-2010-0641

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5 allows remote attackers to inject arbitrary web script or HTML via the dest parameter.

    Source:s4squatch
    Published:17 Feb 2010
    7.5
    High

    CVE-2010-0632

    Last Modified: 17 Jan 2017

    SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action to index.php.

    Source:AtT4CKxT3rR0r1ST
    Published:12 Feb 2010
    7.5
    High

    CVE-2010-0631

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow remote attackers to execute arbitrary SQL commands via the (1) users (username) and (2) passwords parameters.

    Source:Hamza 'MizoZ' N.
    Published:12 Feb 2010
    7.5
    High

    CVE-2010-0630

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in viewjokes.php in Evernew Free Joke Script 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hamza 'MizoZ' N.
    Published:12 Feb 2010
    9.3
    Critical

    CVE-2010-0620

    Last Modified: 28 Apr 2011

    Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter.

    Source:Metasploit
    Published:25 Feb 2010
    7.3
    High

    CVE-2010-0619

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser printers and multi-function printers allows remote attackers to execute arbitrary code or cause a denial of service (device hang) via a long argument to a PJL INQUIRE command.

    Source:Francis Provencher
    Published:24 Mar 2010
    7.5
    High

    CVE-2010-0614

    Last Modified: 1 Jun 2014

    SQL injection vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to execute arbitrary SQL commands via the query parameter in the (1) question action, and possibly the (2) sub_par or (3) num_quest actions.

    Source:ekse
    Published:11 Feb 2010
    7.5
    High

    CVE-2010-0611

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Source:cr4wl3r
    Published:11 Feb 2010
    7.5
    High

    CVE-2010-0610

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the blog parameter in an images action to index.php. NOTE: a separate vector for the id parameter to detail.php may also exist.

    Source:ALTBTA
    Published:11 Feb 2010
    7.5
    High

    CVE-2010-0608

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter in a search action.

    Source:Delibey
    Published:11 Feb 2010
    4.3
    Medium

    CVE-2010-0607

    Last Modified: 1 Jul 2014

    Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote attackers to inject arbitrary web script or HTML via the Stat_Radio parameter.

    Source:Karn Ganeshen
    Published:11 Feb 2010
    7.5
    High

    CVE-2010-0605

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.

    Source:Nahuel Grisolia
    Published:11 Feb 2010
    7.5
    High

    CVE-2010-0557

    Last Modified: 27 Oct 2016

    IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials.

    Source:Metasploit
    Published:5 Feb 2010
    6.5
    Medium

    CVE-2010-0553

    Last Modified: 4 Jul 2014

    Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a long NMEA data sentence.

    Source:RedTeam Pentesting GmbH
    Published:4 Feb 2010
    7.5
    High

    CVE-2010-0552

    Last Modified: 11 Jul 2017

    Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via multiple requests for a non-existent file using a long URI.

    Source:RedTeam Pentesting GmbH
    Published:4 Feb 2010
    6.8
    Medium

    CVE-2010-0520

    Last Modified: 18 Sept 2010

    Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC file, related to crafted DELTA_FLI chunks and untrusted length values in a .fli file, which are not properly handled during decompression.

    Source:Abysssec
    Published:30 Mar 2010
    6.8
    Medium

    CVE-2010-0519

    Last Modified: 4 Sept 2010

    Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Stream containing a NumberOfTiles field with a large value.

    Source:Abysssec
    Published:30 Mar 2010
    5
    Medium

    CVE-2010-0496

    Last Modified: 11 Apr 2025

    FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) via a HEAD request for the / URI.

    Source:mr_me
    Published:3 Feb 2010
    7.6
    High

    CVE-2010-0483

    Last Modified: 10 Mar 2011

    vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability."

    Source:Metasploit
    Published:3 Mar 2010
    9.3
    Critical

    CVE-2010-0480

    Last Modified: 24 Sept 2010

    Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted AVI file, aka "MPEG Layer-3 Audio Decoder Stack Overflow Vulnerability."

    Source:Abysssec
    Published:14 Apr 2010
    9.3
    Critical

    CVE-2010-0478

    Last Modified: 6 Mar 2011

    Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability."

    Source:Metasploit
    Published:14 Apr 2010
    10
    Critical

    CVE-2010-0477

    Last Modified: 20 Feb 2011

    The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the client to read the entirety of the response, and then improperly interact with the Winsock Kernel (WSK), aka "SMB Client Message Size Vulnerability."

    Source:laurent gaffie
    Published:14 Apr 2010
    10
    Critical

    CVE-2010-0476

    Last Modified: 20 Feb 2011

    The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted SMB transaction response that uses (1) SMBv1 or (2) SMBv2, aka "SMB Client Response Parsing Vulnerability."

    Source:laurent gaffie
    Published:14 Apr 2010
    4.3
    Medium

    CVE-2010-0475

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter.

    Source:Jeromie Jackson
    Published:14 May 2010
    4.3
    Medium

    CVE-2010-0470

    Last Modified: 30 May 2014

    Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inject arbitrary web script or HTML via the srvName parameter.

    Source:Yoyahack
    Published:2 Feb 2010
    4.3
    Medium

    CVE-2010-0468

    Last Modified: 30 May 2014

    Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Source:Richard Brain
    Published:2 Feb 2010
    5.8
    Medium

    CVE-2010-0467

    Last Modified: 28 Jul 2017

    Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.

    Source:B-HUNT3|2
    Published:2 Feb 2010
    6.5
    Medium

    CVE-2010-0462

    Last Modified: 30 May 2014

    Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function.

    Source:Evgeny Legerov
    Published:28 Jan 2010