|
295851
|
- |
|
apache
|
tomcat
|
Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows rem…
|
CWE-399
Resource Management Errors
|
CVE-2011-4858
|
2024-11-21 10:33 |
2012-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295852
|
- |
|
textpattern
|
textpattern
|
Cross-site scripting (XSS) vulnerability in setup/index.php in Textpattern CMS 4.4.1, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via th…
|
CWE-79
Cross-site Scripting
|
CVE-2011-5019
|
2024-11-21 10:33 |
2012-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295853
|
- |
|
apache
|
activemq
|
Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
|
CWE-399
Resource Management Errors
|
CVE-2011-4905
|
2024-11-21 10:33 |
2012-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295854
|
- |
|
cocsoft
|
stream_down
|
Stack-based buffer overflow in CoCSoft Stream Down 6.8.0 allows remote web servers to execute arbitrary code via a long response to a download request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2011-5052
|
2024-11-21 10:33 |
2012-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295855
|
- |
|
wpsymposium
|
wp_symposium
|
Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable exte…
|
NVD-CWE-Other
|
CVE-2011-5051
|
2024-11-21 10:33 |
2012-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295856
|
- |
|
elitecore
|
cyberoam_unified_threat_management
|
SQL injection vulnerability in corporate/Controller in Elitecore Technologies Cyberoam UTM before 10.01.2 build 059 allows remote authenticated administrators to execute arbitrary SQL commands via th…
|
CWE-89
SQL Injection
|
CVE-2011-5050
|
2024-11-21 10:33 |
2012-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295857
|
- |
|
-
|
-
|
MySQL 5.5.8, when running on Windows, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted packet to TCP port 3306.
|
CWE-399
Resource Management Errors
|
CVE-2011-5049
|
2024-11-21 10:33 |
2012-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295858
|
- |
|
e107
|
e107
|
SQL injection vulnerability in usersettings.php in e107 0.7.26, and possibly other versions before 1.0.0, allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2011-4921
|
2024-11-21 10:33 |
2012-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295859
|
- |
|
e107
|
e107
|
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.26, and other versions before 1.0.0, allow remote attackers to inject arbitrary web script or HTML via the URL to (1) e107_images/thumb…
|
CWE-79
Cross-site Scripting
|
CVE-2011-4920
|
2024-11-21 10:33 |
2012-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295860
|
- |
|
ibm
|
web_experience_factory
|
Multiple cross-site scripting (XSS) vulnerabilities in IBM Web Experience Factory (aka WEF, formerly WebSphere Portlet Factory) 7.0 and 7.0.1 allow remote attackers to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2011-5048
|
2024-11-21 10:33 |
2012-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|