|
294271
|
- |
|
diy-cms
|
blog
|
Multiple SQL injection vulnerabilities in the blog module 1.0 for DiY-CMS allow remote attackers to execute arbitrary SQL commands via the (1) start parameter to (a) tags.php, (b) list.php, (c) index…
|
CWE-89
SQL Injection
|
CVE-2011-5140
|
2024-11-21 10:33 |
2012-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294272
|
- |
|
preprojects
|
business_cards_designer
|
SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2011-5139
|
2024-11-21 10:33 |
2012-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294273
|
- |
|
tforum
|
tforum
|
Cross-site scripting (XSS) vulnerability in member.php in tForum b0.915 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a viewprofile action.
|
CWE-79
Cross-site Scripting
|
CVE-2011-5138
|
2024-11-21 10:33 |
2012-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294274
|
- |
|
tforum
|
tforum
|
Multiple SQL injection vulnerabilities in tForum b0.915 allow remote attackers to execute arbitrary SQL commands via the (1) TopicID parameter to viewtopic.php, the (2) BoardID parameter to viewboard…
|
CWE-89
SQL Injection
|
CVE-2011-5137
|
2024-11-21 10:33 |
2012-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294275
|
- |
|
epractizelabs
|
subscription_manager
|
showImg.php in EPractize Labs Subscription Manager, possibly 1.0, allows remote attackers to overwrite arbitrary files via the db parameter.
|
CWE-20
Improper Input Validation
|
CVE-2011-5136
|
2024-11-21 10:33 |
2012-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294276
|
- |
|
docebo
|
docebolms
|
Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in DoceboLMS 4.0.4 and earlier allow remote authenticated users with admin or teacher…
|
CWE-89
SQL Injection
|
CVE-2011-5135
|
2024-11-21 10:33 |
2012-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294277
|
- |
|
widgetfactorylimited
|
com_jce
|
Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privileges to execute arb…
|
NVD-CWE-Other
|
CVE-2011-5134
|
2024-11-21 10:33 |
2012-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294278
|
- |
|
mybb
|
mybb
|
Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list."
|
NVD-CWE-noinfo
|
CVE-2011-5133
|
2024-11-21 10:33 |
2012-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294279
|
- |
|
mybb
|
mybb
|
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX."
|
CWE-79
Cross-site Scripting
|
CVE-2011-5132
|
2024-11-21 10:33 |
2012-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294280
|
- |
|
mybb
|
mybb
|
Cross-site request forgery (CSRF) vulnerability in global.php in MyBB before 1.6.5 allows remote attackers to hijack the authentication of a user for requests that change the user's language via the …
|
CWE-352
Origin Validation Error
|
CVE-2011-5131
|
2024-11-21 10:33 |
2012-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|