|
295551
|
- |
|
infoproject
|
biznis_heroj
|
Multiple cross-site scripting (XSS) vulnerabilities in Infoproject Biznis Heroj allow remote attackers to inject arbitrary web script or HTML via the config parameter to (1) nalozi_naslov.php and (2)…
|
CWE-79
Cross-site Scripting
|
CVE-2011-5040
|
2024-11-21 10:33 |
2011-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295552
|
- |
|
infoproject
|
biznis_heroj
|
Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to login.php, (3) the filt…
|
CWE-89
SQL Injection
|
CVE-2011-5039
|
2024-11-21 10:33 |
2011-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295553
|
- |
|
hitcode
|
hitappoint
|
SQL injection vulnerability in hitCode hitAppoint 4.5.17 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to index.php. NOTE: the provenance …
|
CWE-89
SQL Injection
|
CVE-2011-5038
|
2024-11-21 10:33 |
2011-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295554
|
- |
|
google
|
v8
|
Google V8 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption)…
|
CWE-20
Improper Input Validation
|
CVE-2011-5037
|
2024-11-21 10:33 |
2011-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295555
|
- |
|
rack_project
|
rack
|
Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote atta…
|
CWE-310
Cryptographic Issues
|
CVE-2011-5036
|
2024-11-21 10:33 |
2011-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295556
|
- |
|
oracle
|
glassfish_server
|
Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values for form parameters w…
|
CWE-20
Improper Input Validation
|
CVE-2011-5035
|
2024-11-21 10:33 |
2011-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295557
|
- |
|
apache
|
geronimo
|
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of s…
|
CWE-20
Improper Input Validation
|
CVE-2011-5034
|
2024-11-21 10:33 |
2011-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295558
|
- |
|
php
|
php
|
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consu…
|
CWE-20
Improper Input Validation
|
CVE-2011-4885
|
2024-11-21 10:33 |
2011-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295559
|
- |
|
jruby
|
jruby
|
JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumptio…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2011-4838
|
2024-11-21 10:33 |
2011-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295560
|
- |
|
ruby-lang
|
ruby
|
Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (…
|
CWE-20
Improper Input Validation
|
CVE-2011-4815
|
2024-11-21 10:33 |
2011-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|