|
305831
|
- |
|
cisco
|
internet_streamer content_delivery_system
|
Directory traversal vulnerability in Cisco Internet Streamer, as used in Cisco Content Delivery System (CDS) 2.2.x, 2.3.x, 2.4.x, and 2.5.x before 2.5.7 allows remote attackers to read arbitrary file…
|
CWE-22
Path Traversal
|
CVE-2010-1577
|
2024-11-21 10:14 |
2010-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305832
|
- |
|
cisco
|
ios industrial_ethernet_3000
|
IOS 12.2(52)SE and 12.2(52)SE1 on Cisco Industrial Ethernet (IE) 3000 series switches has (1) a community name of public for RO access and (2) a community name of private for RW access, which makes i…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-1574
|
2024-11-21 10:14 |
2010-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305833
|
- |
|
mahara
|
mahara
|
Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 has improper configuration options for authentication plugins associated with logins that use the single sign-on (SSO) functionality, …
|
CWE-287
Improper Authentication
|
CVE-2010-1670
|
2024-11-21 10:14 |
2010-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305834
|
- |
|
mahara
|
mahara
|
SQL injection vulnerability in Mahara 1.1.x before 1.1.9 and 1.2.x before 1.2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2010-1669
|
2024-11-21 10:14 |
2010-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305835
|
- |
|
mahara
|
mahara
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers to hijack the authentication of unspecified victi…
|
CWE-352
Origin Validation Error
|
CVE-2010-1668
|
2024-11-21 10:14 |
2010-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305836
|
- |
|
mahara
|
mahara
|
Multiple cross-site scripting (XSS) vulnerabilities in Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via unspecified v…
|
CWE-79
Cross-site Scripting
|
CVE-2010-1667
|
2024-11-21 10:14 |
2010-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305837
|
- |
|
cisco
|
content_services_switch_11500 ace_4710
|
The Cisco Content Services Switch (CSS) 11500 with software before 8.20.4.02 and the Application Control Engine (ACE) 4710 with software before A2(3.0) do not properly handle use of LF, CR, and LFCR …
|
CWE-20
Improper Input Validation
|
CVE-2010-1576
|
2024-11-21 10:14 |
2010-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305838
|
- |
|
cisco
|
content_services_switch_11500
|
The Cisco Content Services Switch (CSS) 11500 with software 08.20.1.01 conveys authentication data through ClientCert-* headers but does not delete client-supplied ClientCert-* headers, which might a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-1575
|
2024-11-21 10:14 |
2010-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305839
|
- |
|
tornadostore
|
tornadostore
|
Multiple cross-site scripting (XSS) vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) tipo or (2) destino parameter to login_…
|
CWE-79
Cross-site Scripting
|
CVE-2010-1328
|
2024-11-21 10:14 |
2010-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305840
|
- |
|
tornadostore
|
tornadostore
|
Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where paramete…
|
CWE-89
SQL Injection
|
CVE-2010-1327
|
2024-11-21 10:14 |
2010-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|