|
300301
|
- |
|
qt digia
|
qt
|
QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL ser…
|
CWE-20
Improper Input Validation
|
CVE-2010-5076
|
2024-11-21 10:22 |
2012-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300302
|
- |
|
typo3
|
typo3
|
The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly filter file types, which allows r…
|
CWE-20
Improper Input Validation
|
CVE-2010-5099
|
2024-11-21 10:22 |
2012-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300303
|
- |
|
typo3
|
typo3
|
The escapeStrForLike method in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly escape input when the MySQL database is set to sql_mode NO_BACKSLASH_ESCAPES, wh…
|
CWE-200
Information Exposure
|
CVE-2010-5104
|
2024-11-21 10:22 |
2012-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300304
|
- |
|
typo3
|
typo3
|
SQL injection vulnerability in the list module in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated users with certain permissions to execute arbitrary…
|
CWE-89
SQL Injection
|
CVE-2010-5103
|
2024-11-21 10:22 |
2012-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300305
|
- |
|
typo3
|
typo3
|
Directory traversal vulnerability in mod/tools/em/class.em_unzip.php in the unzip library in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote attackers to write arb…
|
CWE-22
Path Traversal
|
CVE-2010-5102
|
2024-11-21 10:22 |
2012-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300306
|
- |
|
typo3
|
typo3
|
Directory traversal vulnerability in the TypoScript setup in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated administrators to read arbitrary files v…
|
CWE-22
Path Traversal
|
CVE-2010-5101
|
2024-11-21 10:22 |
2012-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300307
|
- |
|
typo3
|
typo3
|
Multiple cross-site scripting (XSS) vulnerabilities in the Install Tool in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allow remote authenticated users to inject arbitrary w…
|
CWE-79
Cross-site Scripting
|
CVE-2010-5100
|
2024-11-21 10:22 |
2012-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300308
|
- |
|
typo3
|
typo3
|
Cross-site scripting (XSS) vulnerability in the FORM content object in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5, allows remote authenticated users to inject arbitrary web…
|
CWE-79
Cross-site Scripting
|
CVE-2010-5098
|
2024-11-21 10:22 |
2012-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300309
|
- |
|
typo3
|
typo3
|
Cross-site scripting (XSS) vulnerability in the click enlarge functionality in TYPO3 4.3.x before 4.3.9 and 4.4.x before 4.4.5 when the caching framework is enabled, allows remote attackers to inject…
|
CWE-79
Cross-site Scripting
|
CVE-2010-5097
|
2024-11-21 10:22 |
2012-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300310
|
- |
|
bitweaver
|
bitweaver
|
Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the style parameter.
|
CWE-22
Path Traversal
|
CVE-2010-5086
|
2024-11-21 10:22 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|