|
296171
|
- |
|
openstack
|
nova
|
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to ov…
|
CWE-22
Path Traversal
|
CVE-2011-4596
|
2024-11-21 10:32 |
2011-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296172
|
- |
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in libraries/config/ConfigFile.class.php in the setup interface in phpMyAdmin 3.4.x before 3.4.9 allows remote attackers to inject arbitrary web script or HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2011-4782
|
2024-11-21 10:32 |
2011-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296173
|
- |
|
phpmyadmin
|
phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL …
|
CWE-79
Cross-site Scripting
|
CVE-2011-4780
|
2024-11-21 10:32 |
2011-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296174
|
- |
|
phpmyadmin
|
phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Data…
|
CWE-79
Cross-site Scripting
|
CVE-2011-4634
|
2024-11-21 10:32 |
2011-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296175
|
- |
|
pmwiki
|
pmwiki
|
The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive,…
|
CWE-94
Code Injection
|
CVE-2011-4453
|
2024-11-21 10:32 |
2011-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296176
|
- |
|
moodle
|
moodle
|
CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and 2.2 allows remote attackers to inject arbitrary H…
|
CWE-94
Code Injection
|
CVE-2011-4203
|
2024-11-21 10:32 |
2011-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296177
|
- |
|
zftpserver
|
zftpserver_suite
|
Directory traversal vulnerability in zFTPServer Suite 6.0.0.52 allows remote authenticated users to delete arbitrary directories via a crafted RMD (aka rmdir) command.
|
CWE-22
Path Traversal
|
CVE-2011-4717
|
2024-11-21 10:32 |
2011-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296178
|
- |
|
unbound
|
unbound
|
Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) …
|
CWE-399
Resource Management Errors
|
CVE-2011-4528
|
2024-11-21 10:32 |
2011-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296179
|
- |
|
pidgin
|
pidgin
|
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attacke…
|
CWE-20
Improper Input Validation
|
CVE-2011-4603
|
2024-11-21 10:32 |
2011-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296180
|
- |
|
pidgin
|
pidgin
|
The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of …
|
CWE-20
Improper Input Validation
|
CVE-2011-4602
|
2024-11-21 10:32 |
2011-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|