|
345411
|
- |
|
georg_greve
|
spamassassin_milter_plugin
|
The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacter…
|
CWE-78
OS Command
|
CVE-2010-1132
|
2017-08-17 10:32 |
2010-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345412
|
- |
|
tiki
|
tikiwiki_cms\/groupware
|
Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) tiki-searchin…
|
CWE-89
SQL Injection
|
CVE-2010-1133
|
2017-08-17 10:32 |
2010-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345413
|
- |
|
tiki
|
tikiwiki_cms\/groupware
|
SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable.
|
CWE-89
SQL Injection
|
CVE-2010-1134
|
2017-08-17 10:32 |
2010-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345414
|
- |
|
tiki
|
tikiwiki_cms\/groupware
|
The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.
|
CWE-255
Credentials Management
|
CVE-2010-1135
|
2017-08-17 10:32 |
2010-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345415
|
- |
|
tiki
|
tikiwiki_cms\/groupware
|
The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictabl…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-1136
|
2017-08-17 10:32 |
2010-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345416
|
- |
|
irssi
|
irssi
|
Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certific…
|
CWE-20
Improper Input Validation
|
CVE-2010-1155
|
2017-08-17 10:32 |
2010-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345417
|
- |
|
irssi
|
irssi
|
core/nicklist.c in Irssi before 0.8.15 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an attempted fuzzy nick match at th…
|
NVD-CWE-Other
|
CVE-2010-1156
|
2017-08-17 10:32 |
2010-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345418
|
- |
|
irssi
|
irssi
|
Per: http://cwe.mitre.org/data/definitions/476.html
'NULL Pointer Dereference'
|
NVD-CWE-Other
|
CVE-2010-1156
|
2017-08-17 10:32 |
2010-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345419
|
- |
|
atlassian
|
jira
|
Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code by modifying the (1) attachment (aka attachments), (2) index (aka indexing), or (3) backup path an…
|
CWE-94
Code Injection
|
CVE-2010-1165
|
2017-08-17 10:32 |
2010-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345420
|
- |
|
atlassian
|
jira
|
Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA 3.12 through 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) element or (2) defaultColor parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2010-1164
|
2017-08-17 10:32 |
2010-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|