|
295031
|
- |
|
ibm
|
websphere_ilog_rule_team_server
|
Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the project parameter to …
|
CWE-79
Cross-site Scripting
|
CVE-2011-4171
|
2024-11-21 10:31 |
2011-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295032
|
- |
|
kent-web
|
web_forum
|
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to "web form entries."
|
CWE-79
Cross-site Scripting
|
CVE-2011-3984
|
2024-11-21 10:31 |
2011-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295033
|
- |
|
kent-web
|
web_forum
|
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to cookies.
|
CWE-79
Cross-site Scripting
|
CVE-2011-3983
|
2024-11-21 10:31 |
2011-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295034
|
- |
|
gnome
|
empathy
|
Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers …
|
CWE-79
Cross-site Scripting
|
CVE-2011-4170
|
2024-11-21 10:31 |
2011-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295035
|
- |
|
xia_zuojie
|
nexusphp
|
SQL injection vulnerability in thanks.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2011-4026
|
2024-11-21 10:31 |
2011-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295036
|
- |
|
ocsinventory-ng
|
ocs_inventory_ng
|
Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4024
|
2024-11-21 10:31 |
2011-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295037
|
- |
|
lockon
|
ec-cube
|
SQL injection vulnerability in data/class/SC_Query.php in EC-CUBE 2.11.0 through 2.11.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2011-3988
|
2024-11-21 10:31 |
2011-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295038
|
- |
|
asterisk
|
open_source
|
chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.7.1 and 10.x before 10.0.0-rc1 does not properly initialize variables during request parsing, which allows remote authent…
|
CWE-20
Improper Input Validation
|
CVE-2011-4063
|
2024-11-21 10:31 |
2011-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295039
|
- |
|
mit
|
kerberos_5
|
The krb5_db2_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4, when the db2 (aka Berkeley DB) back end is used, allows remote attackers to ca…
|
CWE-20
Improper Input Validation
|
CVE-2011-4151
|
2024-11-21 10:31 |
2011-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295040
|
- |
|
djangoproject
|
django
|
The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary HTTP Host headers, which allows remote attackers …
|
CWE-352
Origin Validation Error
|
CVE-2011-4140
|
2024-11-21 10:31 |
2011-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|