|
298941
|
- |
|
webasyst
|
shop-script
|
SQL injection vulnerability in index.php in WebAsyst Shop-Script allows remote attackers to execute arbitrary SQL commands via the blog_id parameter in a news action.
|
CWE-89
SQL Injection
|
CVE-2010-4859
|
2024-11-21 10:21 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298942
|
- |
|
joerg_risse
|
dnet_live-stats
|
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the showlang parameter.
|
CWE-22
Path Traversal
|
CVE-2010-4858
|
2024-11-21 10:21 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298943
|
- |
|
curtiss_grymala
|
cag_cms
|
SQL injection vulnerability in click.php in CAG CMS 0.2 Beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
|
CWE-89
SQL Injection
|
CVE-2010-4857
|
2024-11-21 10:21 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298944
|
- |
|
aspindir
|
xweblog
|
SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.
|
CWE-89
SQL Injection
|
CVE-2010-4856
|
2024-11-21 10:21 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298945
|
- |
|
aspindir
|
xweblog
|
SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-4855
|
2024-11-21 10:21 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298946
|
- |
|
zuitu
|
zuitu
|
SQL injection vulnerability in ajax/coupon.php in Zuitu 1.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a consume action.
|
CWE-89
SQL Injection
|
CVE-2010-4854
|
2024-11-21 10:21 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298947
|
- |
|
chillcreations
|
com_ccinvoices
|
SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewInv action to index.php.
|
CWE-89
SQL Injection
|
CVE-2010-4853
|
2024-11-21 10:21 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298948
|
- |
|
manageengine
|
eventlog_analyzer
|
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine EventLog Analyzer 6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HOST_ID, (2) OS, (3) GROUP, (4) exp…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4841
|
2024-11-21 10:21 |
2011-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298949
|
- |
|
manageengine
|
eventlog_analyzer
|
Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (SysEvttCol.exe process crash) or possibly execute arbitrary c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4840
|
2024-11-21 10:21 |
2011-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298950
|
- |
|
eclime
|
eclime
|
Cross-site scripting (XSS) vulnerability in login.php in Eclime 1.1.2b allows remote attackers to inject arbitrary web script or HTML via the reason parameter in a fail action.
|
CWE-79
Cross-site Scripting
|
CVE-2010-4852
|
2024-11-21 10:21 |
2011-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|