|
294011
|
- |
|
intelliants
|
subrion_cms
|
SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or (2) password field.
|
CWE-89
SQL Injection
|
CVE-2011-5212
|
2024-11-21 10:33 |
2012-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294012
|
- |
|
intelliants
|
subrion_cms
|
Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the title field. NOTE: some of these details are o…
|
CWE-79
Cross-site Scripting
|
CVE-2011-5211
|
2024-11-21 10:33 |
2012-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294013
|
- |
|
limny
|
limny
|
Directory traversal vulnerability in admin/preview.php in Limny 3.0.0 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the theme parameter.
|
CWE-22
Path Traversal
|
CVE-2011-5210
|
2024-11-21 10:33 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294014
|
- |
|
cloneforest
|
graphicsclone_script
|
Cross-site scripting (XSS) vulnerability in search/ in GraphicsClone Script, possibly 1.11, allows remote attackers to inject arbitrary web script or HTML via the term parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2011-5209
|
2024-11-21 10:33 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294015
|
- |
|
backwpup
|
backwpup
|
Multiple directory traversal vulnerabilities in the BackWPup plugin before 1.4.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the wpabs parameter to (1) app/opti…
|
CWE-22
Path Traversal
|
CVE-2011-5208
|
2024-11-21 10:33 |
2012-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294016
|
- |
|
redmine
|
redmine
|
Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2011-4929
|
2024-11-21 10:33 |
2012-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294017
|
- |
|
redmine
|
redmine
|
Cross-site scripting (XSS) vulnerability in the textile formatter in Redmine before 1.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4928
|
2024-11-21 10:33 |
2012-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294018
|
- |
|
redmine
|
redmine
|
Unspecified vulnerability in the bazaar repository adapter in Redmine 1.0.x before 1.0.5 allows remote authenticated users to obtain sensitive information via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2011-4927
|
2024-11-21 10:33 |
2012-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294019
|
- |
|
joomla
|
joomla\!
|
Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attackers to obtain the installation path via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2011-4911
|
2024-11-21 10:33 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294020
|
- |
|
joomla
|
joomla\!
|
Cross-site scripting (XSS) vulnerability in Joomla! before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4910
|
2024-11-21 10:33 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|