|
287421
|
- |
|
letodms
|
letodms
|
Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) 1.7.2 and earlier allow remote attackers to hijack the authentication of administrators for requests that use (1…
|
CWE-352
Origin Validation Error
|
CVE-2010-2007
|
2018-10-11 04:58 |
2010-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287422
|
- |
|
createch-group
|
lisk_cms
|
Cross-site scripting (XSS) vulnerability in cp/edit_email.php in LiSK CMS 4.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2013
|
2018-10-11 04:58 |
2010-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287423
|
- |
|
exim
|
exim
|
transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial o…
|
CWE-362
Race Condition
|
CVE-2010-2023
|
2018-10-11 04:58 |
2010-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287424
|
- |
|
exim
|
exim
|
transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possi…
|
CWE-362
Race Condition
|
CVE-2010-2024
|
2018-10-11 04:58 |
2010-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287425
|
- |
|
wolfram_research
|
mathematica
|
Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf.
|
CWE-59
Link Following
|
CVE-2010-2027
|
2018-10-11 04:58 |
2010-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287426
|
- |
|
caucho
|
resin
|
Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to injec…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2032
|
2018-10-11 04:58 |
2010-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287427
|
- |
|
gpeasy
|
gpeasy_cms
|
Cross-site scripting (XSS) vulnerability in include/tool/editing_files.php in gpEasy CMS 1.6.2 allows remote authenticated users, with Edit privileges, to inject arbitrary web script or HTML via the …
|
CWE-79
Cross-site Scripting
|
CVE-2010-2038
|
2018-10-11 04:58 |
2010-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287428
|
- |
|
php-calendar
|
php-calendar
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary web script or HTML via the (1) description and (2) lastact…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2041
|
2018-10-11 04:58 |
2010-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287429
|
- |
|
timo_gaik
|
webby_webserver
|
Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2102
|
2018-10-11 04:58 |
2010-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287430
|
- |
|
apache
|
axis2
|
Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Busin…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2103
|
2018-10-11 04:58 |
2010-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|