|
300141
|
- |
|
vwar
|
virtual_war
|
The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select the seed argument for the PHP mt_srand function, which mak…
|
CWE-310
Cryptographic Issues
|
CVE-2010-5066
|
2024-11-21 10:22 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300142
|
- |
|
vwar
|
virtual_war
|
popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modified newsid parameter in a printnews action.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-5065
|
2024-11-21 10:22 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300143
|
- |
|
vwar
|
virtual_war
|
Multiple cross-site scripting (XSS) vulnerabilities in Virtual War (aka VWar) 1.6.1 R2 allow remote attackers to inject arbitrary web script or HTML via (1) the Additional Information field to challe…
|
CWE-79
Cross-site Scripting
|
CVE-2010-5064
|
2024-11-21 10:22 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300144
|
- |
|
vwar
|
virtual_war
|
SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the ratearticleselect parameter.
|
CWE-89
SQL Injection
|
CVE-2010-5063
|
2024-11-21 10:22 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300145
|
- |
|
modx
|
modx_revolution
|
Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read…
|
CWE-22
Path Traversal
|
CVE-2010-5278
|
2024-11-21 10:22 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300146
|
- |
|
karim_ratib
|
views_bulk_operations
|
Unspecified vulnerability in the Views Bulk Operations module 6 before 6.x-1.10 for Drupal allows remote authenticated users with user management permissions to bypass intended access restrictions an…
|
NVD-CWE-noinfo
|
CVE-2010-5277
|
2024-11-21 10:22 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300147
|
- |
|
memcache_project
|
memcache
|
The Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal does not properly handle the $user object in memcache_admin, which might "lead to a role change not being recognized until th…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-5276
|
2024-11-21 10:22 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300148
|
- |
|
memcache_project
|
memcache
|
Cross-site scripting (XSS) vulnerability in memcache_admin in the Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal allows remote attackers to inject arbitrary web script or HTML …
|
CWE-79
Cross-site Scripting
|
CVE-2010-5275
|
2024-11-21 10:22 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300149
|
- |
|
silverstripe
|
silverstripe
|
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) "forgot password" functionality, and (4) pas…
|
CWE-310
Cryptographic Issues
|
CVE-2010-5079
|
2024-11-21 10:22 |
2012-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300150
|
- |
|
silverstripe
|
silverstripe
|
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain version information v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-5078
|
2024-11-21 10:22 |
2012-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|