VYPR

CVEs

346,434 total · page 5968 of 6,929

  • CVE-2010-5042Nov 2, 2011
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the cid[] parameter in an editItem action to administrator/index.php. NOTE: some of these details are…

  • CVE-2010-5041Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands via the id parameter in a plugin action.

  • CVE-2010-5040Nov 2, 2011
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary PHP code via a URL in the DIR_NUCLEUS parameter. NOTE: some of these details are obtained from third party…

  • CVE-2010-5039Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information.

  • CVE-2010-5038Nov 2, 2011
    risk 0.00cvss epss 0.02

    PHP remote file inclusion vulnerability in contact/contact.php in Groone's Simple Contact Form allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

  • CVE-2010-5037Nov 2, 2011
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter.

  • CVE-2010-5036Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.

  • CVE-2010-5035Nov 2, 2011
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka the search field). NOTE: some of these details are obtained from third party information.

  • CVE-2010-5034Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the planid parameter.

  • CVE-2010-5033Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL commands via the CatDisplay parameter.

  • CVE-2010-5032Nov 2, 2011
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a bfquiztrial action to index.php.

  • CVE-2010-5031Nov 2, 2011
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in fileNice 1.1 allows remote attackers to inject arbitrary web script or HTML via the sstring parameter (aka the Search Box). NOTE: some of these details are obtained from third party information.

  • CVE-2010-5030Nov 2, 2011
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to inject arbitrary web script or HTML via the lang parameter in a web action.

  • CVE-2010-5029Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the show parameter in a web action.

  • CVE-2010-5028Nov 2, 2011
    risk 0.04cvss epss 0.09

    SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php.

  • CVE-2010-5027Nov 2, 2011
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2010-5026Nov 2, 2011
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2010-5025Nov 2, 2011
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to inject arbitrary web script or HTML via the fld_path parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2010-5024Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, with Read privileges, to execute arbitrary SQL commands via the user_id parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2010-5023Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID parameter.

  • CVE-2010-5022Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the JExtensions JE Story Submit (com_jesubmit) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.

  • CVE-2010-5021Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intGroupID parameter.

  • CVE-2010-5020Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.

  • CVE-2010-5019Nov 2, 2011
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arbitrary SQL commands via the alb parameter.

  • CVE-2010-5018Nov 2, 2011
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML via the sid parameter.

  • CVE-2010-5017Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in stats.php in Elite Gaming Ladders 3.0 allows remote attackers to execute arbitrary SQL commands via the account parameter.

  • CVE-2010-5016Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in matchdb.php in Elite Gaming Ladders 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the match parameter.

  • CVE-2010-5015Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in view_photo.php in 2daybiz Network Community Script allows remote attackers to execute arbitrary SQL commands via the alb parameter.

  • CVE-2010-5014Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter.

  • CVE-2010-5013Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows remote attackers to execute arbitrary SQL commands via the Lid parameter.

  • CVE-2010-5012Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in new.php in DaLogin 2.2 and 2.2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2010-5011Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to execute arbitrary SQL commands via the session parameter.

  • CVE-2010-5010Nov 2, 2011
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to inject arbitrary web script or HTML via the session parameter.

  • CVE-2010-5009Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action.

  • CVE-2010-5008Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to execute arbitrary SQL commands via the ContactID parameter.

  • CVE-2010-5007Nov 2, 2011
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers to inject arbitrary web script or HTML via the mid parameter.

  • CVE-2010-5006Nov 2, 2011
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in googlemap/index.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the cat1 parameter.

  • CVE-2010-5005Nov 2, 2011
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in members/profileCommentsResponse.php in Rayzz Photoz allows remote attackers to inject arbitrary web script or HTML via the profileCommentTextArea parameter. NOTE: the provenance of this information is unknown; the details are obtained…

  • CVE-2010-5004Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in searchvote.php in 2daybiz Polls (aka Advanced Poll) Script allows remote attackers to execute arbitrary SQL commands via the category parameter.

  • CVE-2010-5000Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the myusername parameter (aka Username field) in a do_login action. NOTE: some of these details are obtained from third party…

  • CVE-2010-4998Nov 2, 2011
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in ardeaCore/lib/core/ardeaInit.php in ardeaCore PHP Framework 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the pathForArdeaCore parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2010-4997Nov 2, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in OlyKit Swoopo Clone 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter in a product action.

  • CVE-2010-4971Nov 2, 2011
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way Video Chat component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the r parameter to index.php.

  • CVE-2011-4075Nov 2, 2011
    risk 0.07cvss epss 0.52

    The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October 2011.

  • CVE-2011-4074Nov 2, 2011
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command.

  • CVE-2011-3320Nov 2, 2011
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Web Administrator component in GE Intelligent Platforms Proficy Historian 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

  • CVE-2011-3167Nov 2, 2011
    risk 0.08cvss epss 0.66

    Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1210.

  • CVE-2011-3166Nov 2, 2011
    risk 0.01cvss epss 0.12

    Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1209.

  • CVE-2011-3165Nov 2, 2011
    risk 0.01cvss epss 0.12

    Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1208.

  • CVE-2011-1919Nov 2, 2011
    risk 0.00cvss epss 0.05

    Multiple stack-based buffer overflows in GE Intelligent Platforms Proficy Applications before 4.4.1 SIM 101 and 5.x before 5.0 SIM 43 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic to (1)…