|
300611
|
- |
|
orangehrm
|
orangehrm
|
Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the uri parameter.
|
CWE-22
Path Traversal
|
CVE-2010-4798
|
2024-11-21 10:21 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300612
|
- |
|
truworthit
|
flex_timesheet
|
Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
|
CWE-89
SQL Injection
|
CVE-2010-4797
|
2024-11-21 10:21 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300613
|
- |
|
phpyun
|
phpyun
|
Multiple SQL injection vulnerabilities in PHPYun 1.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) provinceid parameter to search.php and the (2) e parameter to resumeview.ph…
|
CWE-89
SQL Injection
|
CVE-2010-4796
|
2024-11-21 10:21 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300614
|
- |
|
joomlaseller
|
com_jscalendar
|
SQL injection vulnerability in the JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ev_id parameter in a details ac…
|
CWE-89
SQL Injection
|
CVE-2010-4795
|
2024-11-21 10:21 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300615
|
- |
|
joomlaseller
|
com_jscalendar
|
Multiple cross-site scripting (XSS) vulnerabilities in the JoomlaSeller JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allow remote attackers to inject arbitrary web script or HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4794
|
2024-11-21 10:21 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300616
|
- |
|
site2nite
|
auto_e-manager
|
SQL injection vulnerability in detail.asp in Site2Nite Auto e-Manager allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
CWE-89
SQL Injection
|
CVE-2010-4793
|
2024-11-21 10:21 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300617
|
- |
|
openit
|
overlook
|
Cross-site scripting (XSS) vulnerability in title.php in OPEN IT OverLook 5.0 allows remote attackers to inject arbitrary web script or HTML via the frame parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-4792
|
2024-11-21 10:21 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300618
|
- |
|
marcusg
|
mg_user_fotoalbum_panel
|
SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execut…
|
CWE-89
SQL Injection
|
CVE-2010-4791
|
2024-11-21 10:21 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300619
|
- |
|
in-mediakg
|
filterftp
|
Directory traversal vulnerability in FilterFTP 2.0.3, 2.0.5, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: so…
|
CWE-22
Path Traversal
|
CVE-2010-4790
|
2024-11-21 10:21 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300620
|
- |
|
ibm
|
tivoli_directory_server
|
Use-after-free vulnerability in the proxy-server implementation in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.65 (aka 6.0.0.8-TIV-ITDS-IF0007) and 6.3 before 6.3.0.1 (aka 6.3.0.0-TIV-ITDS-IF0…
|
CWE-399
Resource Management Errors
|
CVE-2010-4789
|
2024-11-21 10:21 |
2011-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|