|
303581
|
- |
|
vincent_fourmond
|
pmount
|
The make_lockdir_name function in policy.c in pmount 0.9.18 allow local users to overwrite arbitrary files via a symlink attack on a file in /var/lock/.
|
CWE-59
Link Following
|
CVE-2010-2192
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303582
|
- |
|
idevspot
|
textads
|
SQL injection vulnerability in index.php in IDevSpot TextAds 2.08 allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2319
|
2024-11-21 10:16 |
2010-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303583
|
- |
|
phpcityportal
|
phpcityportal
|
Cross-site scripting (XSS) vulnerability in cms_data.php in PHPCityPortal 1.3 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2318
|
2024-11-21 10:16 |
2010-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303584
|
- |
|
wmsdesign
|
wmscms
|
Multiple SQL injection vulnerabilities in WmsCms 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) search, (2) sbr, (3) pid, (4) sbl, and (5) FilePath parameters to…
|
CWE-89
SQL Injection
|
CVE-2010-2317
|
2024-11-21 10:16 |
2010-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303585
|
- |
|
wmsdesign
|
wmscms
|
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) sbr, (3) p, and (4) …
|
CWE-79
Cross-site Scripting
|
CVE-2010-2316
|
2024-11-21 10:16 |
2010-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303586
|
- |
|
smartisoft
|
phpbazar
|
PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cat parameter.
|
CWE-94
Code Injection
|
CVE-2010-2315
|
2024-11-21 10:16 |
2010-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303587
|
- |
|
edmondhui.homeip
|
np_twitter
|
PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is enabled, allows remote attackers to execute arbitr…
|
CWE-94
Code Injection
|
CVE-2010-2314
|
2024-11-21 10:16 |
2010-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303588
|
- |
|
anodyne-productions
|
simm_management_system
|
Directory traversal vulnerability in index.php in Anodyne Productions SIMM Management System (SMS) 2.6.10, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. …
|
CWE-22
Path Traversal
|
CVE-2010-2313
|
2024-11-21 10:16 |
2010-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303589
|
- |
|
hauntmax
|
haunted_house_directory_listing_cms
|
SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to execute arbitrary SQL commands via the state parameter in a listings action.
|
CWE-89
SQL Injection
|
CVE-2010-2312
|
2024-11-21 10:16 |
2010-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303590
|
- |
|
power-tab
|
power_tab_editor
|
Stack-based buffer overflow in Power Tab Editor 1.7 build 80 allows user-assisted remote attackers to execute arbitrary code via a .ptb file with a long font name.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2311
|
2024-11-21 10:16 |
2010-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|