|
300991
|
- |
|
joerg_risse
|
dnet_live-stats
|
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the showlang parameter.
|
CWE-22
Path Traversal
|
CVE-2010-4858
|
2024-11-21 10:21 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300992
|
- |
|
curtiss_grymala
|
cag_cms
|
SQL injection vulnerability in click.php in CAG CMS 0.2 Beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
|
CWE-89
SQL Injection
|
CVE-2010-4857
|
2024-11-21 10:21 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300993
|
- |
|
aspindir
|
xweblog
|
SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.
|
CWE-89
SQL Injection
|
CVE-2010-4856
|
2024-11-21 10:21 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300994
|
- |
|
aspindir
|
xweblog
|
SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-4855
|
2024-11-21 10:21 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300995
|
- |
|
zuitu
|
zuitu
|
SQL injection vulnerability in ajax/coupon.php in Zuitu 1.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a consume action.
|
CWE-89
SQL Injection
|
CVE-2010-4854
|
2024-11-21 10:21 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300996
|
- |
|
chillcreations
|
com_ccinvoices
|
SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewInv action to index.php.
|
CWE-89
SQL Injection
|
CVE-2010-4853
|
2024-11-21 10:21 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300997
|
- |
|
manageengine
|
eventlog_analyzer
|
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine EventLog Analyzer 6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HOST_ID, (2) OS, (3) GROUP, (4) exp…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4841
|
2024-11-21 10:21 |
2011-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300998
|
- |
|
manageengine
|
eventlog_analyzer
|
Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (SysEvttCol.exe process crash) or possibly execute arbitrary c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4840
|
2024-11-21 10:21 |
2011-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300999
|
- |
|
eclime
|
eclime
|
Cross-site scripting (XSS) vulnerability in login.php in Eclime 1.1.2b allows remote attackers to inject arbitrary web script or HTML via the reason parameter in a fail action.
|
CWE-79
Cross-site Scripting
|
CVE-2010-4852
|
2024-11-21 10:21 |
2011-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301000
|
- |
|
eclime
|
eclime
|
Multiple SQL injection vulnerabilities in Eclime 1.1.2b allow remote attackers to execute arbitrary SQL commands via the (1) ref or (2) poll_id parameter to index.php, or the (3) country parameter to…
|
CWE-89
SQL Injection
|
CVE-2010-4851
|
2024-11-21 10:21 |
2011-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|