|
300131
|
- |
|
cstech
|
webconductor
|
SQL injection vulnerability in default.php in Cornerstone Technologies webConductor allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-5287
|
2024-11-21 10:22 |
2013-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300132
|
- |
|
joobi
|
com_jstore
|
Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the con…
|
CWE-22
Path Traversal
|
CVE-2010-5286
|
2024-11-21 10:22 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300133
|
- |
|
o-dyn
|
collabtive
|
Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrators for requests that add administrative users via …
|
CWE-352
Origin Validation Error
|
CVE-2010-5285
|
2024-11-21 10:22 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300134
|
- |
|
o-dyn
|
collabtive
|
Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) User parameter in the edit user profile feature to ma…
|
CWE-79
Cross-site Scripting
|
CVE-2010-5284
|
2024-11-21 10:22 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300135
|
- |
|
opentext
|
livelink_ecm
|
Cross-site request forgery (CSRF) vulnerability in OpenText ECM (formerly Livelink ECM) 9.7.1 allows remote attackers to hijack the authentication of administrators for requests that change folder an…
|
CWE-352
Origin Validation Error
|
CVE-2010-5283
|
2024-11-21 10:22 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300136
|
- |
|
opentext
|
livelink_ecm
|
Multiple cross-site scripting (XSS) vulnerabilities in OpenText ECM (formerly Livelink ECM) 9.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewType and (2) sort param…
|
CWE-79
Cross-site Scripting
|
CVE-2010-5282
|
2024-11-21 10:22 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300137
|
- |
|
net4visions
|
ibrowser
|
Directory traversal vulnerability in ibrowser.php in the CMScout 2.09 IBrowser TinyMCE Plugin 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot d…
|
CWE-22
Path Traversal
|
CVE-2010-5281
|
2024-11-21 10:22 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300138
|
- |
|
joomla-cbe
|
com_cbe
|
Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 for Joomla! allows remote attackers to include and execute arbitrary local files…
|
CWE-22
Path Traversal
|
CVE-2010-5280
|
2024-11-21 10:22 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300139
|
- |
|
vwar
|
virtual_war
|
article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to cause a denial of service (memory consumption) via a large integer in the ratearticleselect parameter.
|
CWE-189
Numeric Errors
|
CVE-2010-5279
|
2024-11-21 10:22 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300140
|
- |
|
vwar
|
virtual_war
|
Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attackers to bypass timeout and logout actions, and retain access f…
|
CWE-255
Credentials Management
|
CVE-2010-5067
|
2024-11-21 10:22 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|