|
306231
|
- |
|
wmsdesign
|
wmscms
|
Multiple SQL injection vulnerabilities in WmsCms 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) search, (2) sbr, (3) pid, (4) sbl, and (5) FilePath parameters to…
|
CWE-89
SQL Injection
|
CVE-2010-2317
|
2024-11-21 10:16 |
2010-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306232
|
- |
|
wmsdesign
|
wmscms
|
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) sbr, (3) p, and (4) …
|
CWE-79
Cross-site Scripting
|
CVE-2010-2316
|
2024-11-21 10:16 |
2010-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306233
|
- |
|
smartisoft
|
phpbazar
|
PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cat parameter.
|
CWE-94
Code Injection
|
CVE-2010-2315
|
2024-11-21 10:16 |
2010-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306234
|
- |
|
edmondhui.homeip
|
np_twitter
|
PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is enabled, allows remote attackers to execute arbitr…
|
CWE-94
Code Injection
|
CVE-2010-2314
|
2024-11-21 10:16 |
2010-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306235
|
- |
|
anodyne-productions
|
simm_management_system
|
Directory traversal vulnerability in index.php in Anodyne Productions SIMM Management System (SMS) 2.6.10, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. …
|
CWE-22
Path Traversal
|
CVE-2010-2313
|
2024-11-21 10:16 |
2010-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306236
|
- |
|
hauntmax
|
haunted_house_directory_listing_cms
|
SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to execute arbitrary SQL commands via the state parameter in a listings action.
|
CWE-89
SQL Injection
|
CVE-2010-2312
|
2024-11-21 10:16 |
2010-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306237
|
- |
|
power-tab
|
power_tab_editor
|
Stack-based buffer overflow in Power Tab Editor 1.7 build 80 allows user-assisted remote attackers to execute arbitrary code via a .ptb file with a long font name.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2311
|
2024-11-21 10:16 |
2010-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306238
|
- |
|
solarwinds
|
tftp_server
|
SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request.
|
CWE-20
Improper Input Validation
|
CVE-2010-2310
|
2024-11-21 10:16 |
2010-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306239
|
- |
|
evological
|
evocam
|
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary code via a long GET request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2309
|
2024-11-21 10:16 |
2010-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306240
|
- |
|
sophos
|
anti-virus
|
Unspecified vulnerability in the filter driver (savonaccessfilter.sys) in Sophos Anti-Virus before 7.6.20 allows local users to gain privileges via crafted arguments to the NtQueryAttributesFile func…
|
NVD-CWE-noinfo
|
CVE-2010-2308
|
2024-11-21 10:16 |
2010-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|