|
302981
|
- |
|
ibm
|
lotus_connections
|
The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for remote attackers to ob…
|
NVD-CWE-Other
|
CVE-2010-2278
|
2024-11-21 10:16 |
2010-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302982
|
- |
|
ibm
|
lotus_connections
|
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create or (2) edit form in …
|
CWE-79
Cross-site Scripting
|
CVE-2010-2277
|
2024-11-21 10:16 |
2010-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302983
|
- |
|
dojotoolkit
|
dojo
|
The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 has the copyTests=tru…
|
CWE-16
Configuration
|
CVE-2010-2276
|
2024-11-21 10:16 |
2010-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302984
|
- |
|
dojotoolkit
|
dojo
|
Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demo…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2275
|
2024-11-21 10:16 |
2010-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302985
|
- |
|
dojotoolkit
|
dojo
|
Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbit…
|
NVD-CWE-Other
|
CVE-2010-2274
|
2024-11-21 10:16 |
2010-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302986
|
- |
|
dojotoolkit
|
dojo
|
Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to inject arb…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2273
|
2024-11-21 10:16 |
2010-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302987
|
- |
|
dojotoolkit
|
dojo
|
Unspecified vulnerability in iframe_history.html in Dojo 0.4.x before 0.4.4 has unknown impact and remote attack vectors.
|
NVD-CWE-noinfo
|
CVE-2010-2272
|
2024-11-21 10:16 |
2010-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302988
|
- |
|
accoria
|
rock_web_server
|
Format string vulnerability in authcfg.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to have an unspecified impact via format string specifiers in the path (aka Passwo…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2010-2271
|
2024-11-21 10:16 |
2010-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302989
|
- |
|
accoria
|
rock_web_server
|
Accoria Web Server (aka Rock Web Server) 1.4.7 uses a predictable httpmod-sessionid cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie.
|
CWE-310
Cryptographic Issues
|
CVE-2010-2270
|
2024-11-21 10:16 |
2010-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302990
|
- |
|
accoria
|
rock_web_server
|
Directory traversal vulnerability in loadstatic.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.
|
CWE-22
Path Traversal
|
CVE-2010-2269
|
2024-11-21 10:16 |
2010-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|