|
295221
|
9.8 |
CRITICAL
Network
|
fluxbb
|
fluxbb
|
A reverse proxy issue exists in FluxBB before 1.4.7 when FORUM_BEHIND_REVERSE_PROXY is enabled.
|
NVD-CWE-noinfo
|
CVE-2011-3621
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295222
|
9.8 |
CRITICAL
Network
|
vanillaforums
|
vanilla
|
An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.
|
NVD-CWE-Other
|
CVE-2011-3614
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295223
|
7.5 |
HIGH
Network
|
vanillaforums
|
vanilla
|
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
|
CWE-200
Information Exposure
|
CVE-2011-3613
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295224
|
8.8 |
HIGH
Network
|
usebb
|
usebb
|
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
|
CWE-352
Origin Validation Error
|
CVE-2011-3612
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295225
|
7.2 |
HIGH
Network
|
usebb
|
usebb
|
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
|
CWE-20
Improper Input Validation
|
CVE-2011-3611
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295226
|
6.1 |
MEDIUM
Network
|
s9y
|
serendipity_event_freetag
|
A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud parameter to plugins/serendipity_event_freetag/tagcloud.swf.
|
CWE-79
Cross-site Scripting
|
CVE-2011-3610
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295227
|
5.4 |
MEDIUM
Network
|
joomla
|
joomla\!
|
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2011-3595
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295228
|
8.8 |
HIGH
Network
|
anelectron
|
advanced_electron_forums
|
A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.
|
CWE-352
Origin Validation Error
|
CVE-2011-3582
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295229
|
4.7 |
MEDIUM
Local
|
samba redhat
|
samba enterprise_linux
|
Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a denial of service (mounting outage) via a SIGKILL signal during a time window whe…
|
CWE-362
Race Condition
|
CVE-2011-3585
|
2024-11-21 10:30 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295230
|
7.1 |
HIGH
Local
|
hardlink_project redhat debian
|
hardlink enterprise_linux debian_linux
|
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
|
CWE-59
Link Following
|
CVE-2011-3632
|
2024-11-21 10:30 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|