|
345551
|
- |
|
aspindir
|
krm_haber
|
KrM Haber 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for d_atabase/Krmdb.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-1736
|
2017-08-17 10:32 |
2010-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345552
|
- |
|
joomla
|
com_newsfeeds
|
SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the feedid parameter in a categories action to index.p…
|
CWE-89
SQL Injection
|
CVE-2010-1739
|
2017-08-17 10:32 |
2010-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345553
|
- |
|
freeguppy
|
guppy
|
SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands via the lng parameter.
|
CWE-89
SQL Injection
|
CVE-2010-1740
|
2017-08-17 10:32 |
2010-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345554
|
- |
|
billwerx
|
billwerx_rc
|
SQL injection vulnerability in request_account.php in Billwerx RC 5.2.2 PL2 allows remote attackers to execute arbitrary SQL commands via the primary_number parameter.
|
CWE-89
SQL Injection
|
CVE-2010-1741
|
2017-08-17 10:32 |
2010-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345555
|
- |
|
satyadeep
|
scratcher
|
Cross-site scripting (XSS) vulnerability in projects.php in Scratcher allows remote attackers to inject arbitrary web script or HTML via the show parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-1742
|
2017-08-17 10:32 |
2010-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345556
|
- |
|
satyadeep
|
scratcher
|
SQL injection vulnerability in projects.php in Scratcher allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-1743
|
2017-08-17 10:32 |
2010-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345557
|
- |
|
alibabaclone
|
b2b_gold_script
|
SQL injection vulnerability in product.html in B2B Gold Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-1744
|
2017-08-17 10:32 |
2010-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345558
|
- |
|
toolsjx
|
com_grid
|
Multiple cross-site scripting (XSS) vulnerabilities in the Table JX (com_grid) component for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) data_search and (2) rpp …
|
CWE-79
Cross-site Scripting
|
CVE-2010-1746
|
2017-08-17 10:32 |
2010-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345559
|
- |
|
phpscripte24
|
pay_per_watch_\&_bid_auktions_system
|
SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arbitrary SQL commands via the id_auk parameter.
|
CWE-89
SQL Injection
|
CVE-2010-1855
|
2017-08-17 10:32 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345560
|
- |
|
gelembjuk
|
com_smestorage
|
Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controll…
|
CWE-22
Path Traversal
|
CVE-2010-1858
|
2017-08-17 10:32 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|