|
295391
|
7.5 |
HIGH
Network
|
vanillaforums
|
vanilla
|
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
|
CWE-200
Information Exposure
|
CVE-2011-3613
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295392
|
8.8 |
HIGH
Network
|
usebb
|
usebb
|
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
|
CWE-352
Origin Validation Error
|
CVE-2011-3612
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295393
|
7.2 |
HIGH
Network
|
usebb
|
usebb
|
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
|
CWE-20
Improper Input Validation
|
CVE-2011-3611
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295394
|
6.1 |
MEDIUM
Network
|
s9y
|
serendipity_event_freetag
|
A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud parameter to plugins/serendipity_event_freetag/tagcloud.swf.
|
CWE-79
Cross-site Scripting
|
CVE-2011-3610
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295395
|
5.4 |
MEDIUM
Network
|
joomla
|
joomla\!
|
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2011-3595
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295396
|
8.8 |
HIGH
Network
|
anelectron
|
advanced_electron_forums
|
A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.
|
CWE-352
Origin Validation Error
|
CVE-2011-3582
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295397
|
4.7 |
MEDIUM
Local
|
samba redhat
|
samba enterprise_linux
|
Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a denial of service (mounting outage) via a SIGKILL signal during a time window whe…
|
CWE-362
Race Condition
|
CVE-2011-3585
|
2024-11-21 10:30 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295398
|
7.1 |
HIGH
Local
|
hardlink_project redhat debian
|
hardlink enterprise_linux debian_linux
|
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
|
CWE-59
Link Following
|
CVE-2011-3632
|
2024-11-21 10:30 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295399
|
5.3 |
MEDIUM
Network
|
ruby-lang
|
ruby
|
Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Server headers in requests, which might allow remote …
|
CWE-74
Injection
|
CVE-2011-3624
|
2024-11-21 10:30 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295400
|
6.5 |
MEDIUM
Network
|
tahoe-lafs debian
|
tahoe-lafs debian_linux
|
Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.
|
CWE-863
Incorrect Authorization
|
CVE-2011-3617
|
2024-11-21 10:30 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|