|
298651
|
- |
|
troglobit
|
pimd
|
pimd 2.1.5 and possibly earlier versions allows user-assisted local users to overwrite arbitrary files via a symlink attack on (1) pimd.dump when a USR1 signal is sent, or (2) pimd.cache when USR2 is…
|
CWE-59
Link Following
|
CVE-2011-0007
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298652
|
- |
|
joomla
|
com_search
|
Cross-site scripting (XSS) vulnerability in the com_search module for Joomla! 1.0.x through 1.0.15 allows remote attackers to inject arbitrary web script or HTML via the ordering parameter to index.p…
|
CWE-79
Cross-site Scripting
|
CVE-2011-0005
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298653
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows remote attackers to conduct clickjacking attacks via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2011-0003
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298654
|
- |
|
matomo
|
matomo
|
Piwik before 1.1 does not properly limit the number of files stored under tmp/sessions/, which might allow remote attackers to cause a denial of service (inode consumption) by establishing many sessi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-0401
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298655
|
- |
|
matomo
|
matomo
|
Cookie.php in Piwik before 1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmiss…
|
CWE-16
Configuration
|
CVE-2011-0400
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298656
|
- |
|
matomo
|
matomo
|
Piwik before 1.1 does not prevent the rendering of the login form inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a craft…
|
NVD-CWE-Other
|
CVE-2011-0399
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298657
|
- |
|
matomo
|
matomo
|
The Piwik_Common::getIP function in Piwik before 1.1 does not properly determine the client IP address, which allows remote attackers to bypass intended geolocation and logging functionality via (1) …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-0398
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298658
|
- |
|
matomo
|
matomo
|
Multiple cross-site scripting (XSS) vulnerabilities in Piwik before 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2011-0004
|
2024-11-21 10:23 |
2011-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298659
|
- |
|
microsoft
|
internet_explorer
|
Microsoft Internet Explorer on Windows XP allows remote attackers to trigger an incorrect GUI display and have unspecified other impact via vectors related to the DOM implementation, as demonstrated …
|
NVD-CWE-Other
|
CVE-2011-0347
|
2024-11-21 10:23 |
2011-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298660
|
- |
|
microsoft
|
internet_explorer
|
Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (…
|
CWE-399
Resource Management Errors
|
CVE-2011-0346
|
2024-11-21 10:23 |
2011-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|