|
294841
|
- |
|
adrotateplugin
|
adrotate
|
SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the…
|
CWE-89
SQL Injection
|
CVE-2011-4671
|
2024-11-21 10:32 |
2011-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294842
|
- |
|
wordpress
|
wordpress-users
|
SQL injection vulnerability in wp-users.php in WordPress Users plugin 1.3 and possibly earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the uid parameter to index.p…
|
CWE-89
SQL Injection
|
CVE-2011-4669
|
2024-11-21 10:32 |
2011-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294843
|
- |
|
ibm
|
tivoli_netcool\/reporter
|
IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program used with the Apache HTTP Server.
|
CWE-94
Code Injection
|
CVE-2011-4668
|
2024-11-21 10:32 |
2011-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294844
|
- |
|
prestashop
|
prestashop
|
CRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the name paramete…
|
CWE-94
Code Injection
|
CVE-2011-4545
|
2024-11-21 10:32 |
2011-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294845
|
- |
|
vtiger
|
vtiger_crm
|
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) viewname parameter in a CalendarAjax acti…
|
CWE-79
Cross-site Scripting
|
CVE-2011-4670
|
2024-11-21 10:32 |
2011-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294846
|
- |
|
prestashop
|
prestashop
|
Multiple cross-site scripting (XSS) vulnerabilities in Prestashop before 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) address or (2) relativ_base_dir parameter to mod…
|
CWE-79
Cross-site Scripting
|
CVE-2011-4544
|
2024-11-21 10:32 |
2011-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294847
|
- |
|
atmail
|
atmail_open
|
Multiple cross-site scripting (XSS) vulnerabilities in AtMail Open (aka AtMail Open-Source edition) 1.04 allow remote attackers to inject arbitrary web script or HTML via the func parameter to (1) ld…
|
CWE-79
Cross-site Scripting
|
CVE-2011-4540
|
2024-11-21 10:32 |
2011-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294848
|
- |
|
jenkins
|
jenkins
|
Cross-site scripting (XSS) vulnerability in Jenkins Core in Jenkins before 1.438, and 1.409 LTS before 1.409.3 LTS, when a stand-alone container is used, allows remote attackers to inject arbitrary w…
|
CWE-79
Cross-site Scripting
|
CVE-2011-4344
|
2024-11-21 10:32 |
2011-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294849
|
- |
|
geeklog
|
geeklog
|
Multiple cross-site scripting (XSS) vulnerabilities in the story creation feature in Geeklog 1.8.0 allow remote attackers to inject arbitrary web script or HTML via the (1) code or (2) raw BBcode tag…
|
CWE-79
Cross-site Scripting
|
CVE-2011-4647
|
2024-11-21 10:32 |
2011-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294850
|
- |
|
lesterchan
|
wp-postratings
|
SQL injection vulnerability in wp-postratings.php in the WP-PostRatings plugin 1.50, 1.61, and probably other versions before 1.62 for WordPress allows remote authenticated users with the Author role…
|
CWE-94
Code Injection
|
CVE-2011-4646
|
2024-11-21 10:32 |
2011-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|