|
299531
|
- |
|
micronetsoft
|
rv_dealer_website
|
Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL commands via the (1) selStock parameter to search.asp and the (2) orderBy para…
|
CWE-89
SQL Injection
|
CVE-2010-4362
|
2024-11-21 10:20 |
2010-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299532
|
- |
|
jurpo
|
jurpopage
|
Cross-site scripting (XSS) vulnerability in url-gateway.php in Jurpopage 0.2.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the provenance of this info…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4361
|
2024-11-21 10:20 |
2010-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299533
|
- |
|
jurpo
|
jurpopage
|
Multiple SQL injection vulnerabilities in index.php in Jurpopage 0.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) note and (2) pg parameters, different vectors than CVE-2010…
|
CWE-89
SQL Injection
|
CVE-2010-4360
|
2024-11-21 10:20 |
2010-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299534
|
- |
|
jurpo
|
jurpopage
|
SQL injection vulnerability in index.php in Jurpopage 0.2.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.
|
CWE-89
SQL Injection
|
CVE-2010-4359
|
2024-11-21 10:20 |
2010-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299535
|
- |
|
mrcgiguy
|
guestbook
|
Multiple cross-site scripting (XSS) vulnerabilities in gb.cgi in MRCGIGUY (MCG) Guestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, (3) website, a…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4358
|
2024-11-21 10:20 |
2010-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299536
|
- |
|
boka
|
siteengine
|
SQL injection vulnerability in comments.php in SiteEngine 7.1 allows remote attackers to execute arbitrary SQL commands via the module parameter.
|
CWE-89
SQL Injection
|
CVE-2010-4357
|
2024-11-21 10:20 |
2010-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299537
|
- |
|
site2nite
|
big_truck_broker
|
SQL injection vulnerability in news_default.asp in Site2Nite Big Truck Broker allows remote attackers to execute arbitrary SQL commands via the txtSiteId parameter.
|
CWE-89
SQL Injection
|
CVE-2010-4356
|
2024-11-21 10:20 |
2010-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299538
|
- |
|
dadabik
|
dadabik
|
Cross-site scripting (XSS) vulnerability in DaDaBIK before 4.3 beta2, when the insert or edit feature is enabled, allows remote authenticated users to inject arbitrary web script or HTML via the sele…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4355
|
2024-11-21 10:20 |
2010-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299539
|
- |
|
linux suse opensuse debian
|
linux_kernel linux_enterprise_server linux_enterprise_desktop opensuse linux_enterprise_software_development_kit linux_enterprise_real_time_extension debian_linux
|
The copy_semid_to_user function in ipc/sem.c in the Linux kernel before 2.6.36 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kerne…
|
CWE-909
Missing Initialization of Resource
|
CVE-2010-4083
|
2024-11-21 10:20 |
2010-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299540
|
- |
|
linux suse opensuse
|
linux_kernel linux_enterprise_desktop linux_enterprise_server opensuse linux_enterprise_real_time_extension
|
The viafb_ioctl_get_viafb_info function in drivers/video/via/ioctl.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain …
|
CWE-909
Missing Initialization of Resource
|
CVE-2010-4082
|
2024-11-21 10:20 |
2010-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|