|
294851
|
- |
|
hastymail
|
hastymail2
|
Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] parameter in a mailbox Drafts action to the default URI.
|
CWE-89
SQL Injection
|
CVE-2011-4542
|
2024-11-21 10:32 |
2011-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294852
|
- |
|
namazu
|
namazu
|
Cross-site scripting (XSS) vulnerability in Namazu before 2.0.21, when Internet Explorer 6 or 7 is used, allows remote attackers to inject arbitrary web script or HTML via a cookie.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4345
|
2024-11-21 10:32 |
2011-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294853
|
- |
|
apache
|
http_server
|
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use o…
|
CWE-20
Improper Input Validation
|
CVE-2011-4317
|
2024-11-21 10:32 |
2011-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294854
|
- |
|
novell
|
netware
|
Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute arbitrary code or cause a denial of service (abend or NFS outage) …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2011-4191
|
2024-11-21 10:32 |
2011-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294855
|
- |
|
canonical
|
ubuntu_linux
|
The cupshelpers scripts in system-config-printer in Ubuntu 11.04 and 11.10, as used by the automatic printer driver download service, uses an "insecure connection" for queries to the OpenPrinting dat…
|
CWE-20
Improper Input Validation
|
CVE-2011-4405
|
2024-11-21 10:32 |
2011-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294856
|
- |
|
isc
|
bind
|
query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause…
|
NVD-CWE-noinfo
|
CVE-2011-4313
|
2024-11-21 10:32 |
2011-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294857
|
- |
|
codefuture
|
cf_image_hosting_script
|
Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to inject arbitrary web scr…
|
CWE-79
Cross-site Scripting
|
CVE-2011-4572
|
2024-11-21 10:32 |
2011-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294858
|
- |
|
eaimproved
|
com_estateagent
|
SQL injection vulnerability in the Estate Agent (com_estateagent) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showEO action to index.php.
|
CWE-89
SQL Injection
|
CVE-2011-4571
|
2024-11-21 10:32 |
2011-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294859
|
- |
|
takeaweb
|
com_timereturns
|
SQL injection vulnerability in the Time Returns (com_timereturns) component 2.0 and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id paramete…
|
CWE-89
SQL Injection
|
CVE-2011-4570
|
2024-11-21 10:32 |
2011-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294860
|
- |
|
tom_k
|
forum_userbar_plugin
|
SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to execute arbitrary SQL commands via the image2 parameter.
|
CWE-89
SQL Injection
|
CVE-2011-4569
|
2024-11-21 10:32 |
2011-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|