|
294191
|
- |
|
thecartpress
|
thecartpress
|
Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows remote attackers to inject arbitrary web script o…
|
CWE-79
Cross-site Scripting
|
CVE-2011-5207
|
2024-11-21 10:33 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294192
|
- |
|
rapidleech
|
rapidleech
|
Cross-site scripting (XSS) vulnerability in notes.php in Rapidleech before 2.3 rev42 SVN r399 allows remote attackers to inject arbitrary web script or HTML via the notes parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2011-5206
|
2024-11-21 10:33 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294193
|
- |
|
rapidleech
|
rapidleech
|
Cross-site scripting (XSS) vulnerability in audl.php in Rapidleech 2.3 rev42 SVN r358, rev43 SVN r397, and earlier allows remote attackers to inject arbitrary web script or HTML via the links paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2011-5205
|
2024-11-21 10:33 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294194
|
- |
|
akiva
|
webboard
|
Akiva WebBoard 8.x stores passwords in plaintext, which allows local users to obtain sensitive information by reading from the database.
|
CWE-255
Credentials Management
|
CVE-2011-5204
|
2024-11-21 10:33 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294195
|
- |
|
akiva
|
webboard
|
SQL injection vulnerability in WB/Default.asp in Akiva WebBoard before 8 SR 1 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtain…
|
CWE-89
SQL Injection
|
CVE-2011-5203
|
2024-11-21 10:33 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294196
|
- |
|
michael_biebl
|
policykit
|
PolicyKit 0.103 sets the AdminIdentities to "wheel" by default, which allows local users in the wheel group to gain root privileges without authentication.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4945
|
2024-11-21 10:33 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294197
|
- |
|
sysprogs
|
wincdemu
|
BazisVirtualCDBus.sys in WinCDEmu 3.6 allows local users to cause a denial of service (system crash) via the unmount command to batchmnt.exe.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2011-5202
|
2024-11-21 10:33 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294198
|
- |
|
steveyolam
|
tinyguestbook
|
Multiple SQL injection vulnerabilities in sign.php in tinyguestbook allow remote attackers to execute arbitrary SQL commands via the (1) name and (2) msg parameters. NOTE: some of these details are …
|
CWE-89
SQL Injection
|
CVE-2011-5201
|
2024-11-21 10:33 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294199
|
- |
|
dedecms
|
dedecms
|
Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.
|
CWE-89
SQL Injection
|
CVE-2011-5200
|
2024-11-21 10:33 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294200
|
- |
|
steveyolam
|
tinyguestbook
|
Cross-site scripting (XSS) vulnerability in sign.php in tinyguestbook allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2011-5199
|
2024-11-21 10:33 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|