|
303971
|
- |
|
devana
|
devana
|
SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2673
|
2024-11-21 10:17 |
2010-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303972
|
- |
|
ez
|
ez_publish
|
Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) SectionID and (2) SearchTimestamp parameters to the searc…
|
CWE-89
SQL Injection
|
CVE-2010-2672
|
2024-11-21 10:17 |
2010-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303973
|
- |
|
ez
|
ez_publish
|
Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to inject arbitrary web script or HTML via the subTreeItem parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2671
|
2024-11-21 10:17 |
2010-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303974
|
- |
|
brotherscripts
|
recipe_website
|
SQL injection vulnerability in recipedetail.php in BrotherScripts Recipe Website allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2670
|
2024-11-21 10:17 |
2010-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303975
|
- |
|
novo-ws
|
orbis_cms
|
Cross-site scripting (XSS) vulnerability in admin/editors/text/editor-body.php in Orbis CMS 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2669
|
2024-11-21 10:17 |
2010-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303976
|
- |
|
adaptivedisplays
|
alpha_ethernet_adapter_ii_web_manager alpha_ethernet_adapter_ii
|
Unspecified vulnerability in Adaptive Micro Systems ALPHA Ethernet Adapter II Web-Manager 3.40.2 allows remote attackers to bypass authentication and read or write configuration files via unknown vec…
|
CWE-287 NVD-CWE-noinfo
Improper Authentication
|
CVE-2010-2668
|
2024-11-21 10:17 |
2010-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303977
|
- |
|
opera
|
opera_browser
|
Opera before 10.54 on Windows and Mac OS X does not properly enforce permission requirements for widget filesystem access and directory selection, which allows user-assisted remote attackers to creat…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2666
|
2024-11-21 10:17 |
2010-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303978
|
- |
|
opera
|
opera_browser
|
Cross-site scripting (XSS) vulnerability in Opera before 10.54 on Windows and Mac OS X, and before 10.11 on UNIX platforms, allows remote attackers to inject arbitrary web script or HTML via a data: …
|
CWE-79
Cross-site Scripting
|
CVE-2010-2665
|
2024-11-21 10:17 |
2010-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303979
|
- |
|
opera
|
opera_browser
|
Opera before 10.60 allows remote attackers to cause a denial of service (application hang) via certain HTML content that has an unclosed SPAN element with absolute positioning.
|
NVD-CWE-Other
|
CVE-2010-2664
|
2024-11-21 10:17 |
2010-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303980
|
- |
|
opera
|
opera_browser
|
Opera before 10.60 allows remote attackers to cause a denial of service (application hang) via an ended event handler that changes the SRC attribute of an AUDIO element.
|
NVD-CWE-Other
|
CVE-2010-2663
|
2024-11-21 10:17 |
2010-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|