VYPR

CVEs

385,724 total · page 6900 of 7,715

  • CVE-2010-1091Mar 24, 2010
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in contact.php in phpMySite allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) city, (3) email, (4) state, and (5) message parameters.

  • CVE-2010-1090Mar 24, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in phpMySite allows remote attackers to execute arbitrary SQL commands via the action parameter.

  • CVE-2010-1089Mar 24, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in vedi_faq.php in PHP Trouble Ticket 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2010-0437Mar 24, 2010
    risk 0.04cvss —epss 0.12

    The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of service (NULL pointer…

  • CVE-2010-1082Mar 23, 2010
    risk 0.00cvss —epss 0.01

    Multiple directory traversal vulnerabilities in OI.Blogs 1.0.0, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via directory traversal sequences in the (1) theme parameter to loadStyles.php and the (2) scripts parameter to…

  • CVE-2010-1081Mar 23, 2010
    risk 0.04cvss —epss 0.15

    Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

  • CVE-2010-1080Mar 23, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the f parameter.

  • CVE-2010-1079Mar 23, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Sawmill before 7.2.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2010-1078Mar 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in archive.php in XlentProjects SphereCMS 1.1 alpha allows remote attackers to execute arbitrary SQL commands via encoded null bytes ("%00") in the view parameter, which bypasses a protection mechanism.

  • CVE-2010-1077Mar 23, 2010
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the vbseourl parameter.

  • CVE-2010-1076Mar 23, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Entry Level CMS (EL CMS) allows remote attackers to inject arbitrary web script or HTML via the subj parameter, which is not properly handled in a forced SQL error message. NOTE: the provenance of this information is…

  • CVE-2010-1075Mar 23, 2010
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in index.php in Entry Level CMS (EL CMS) allows remote attackers to execute arbitrary SQL commands via the subj parameter.

  • CVE-2010-1074Mar 23, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Currency Exchange module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to watchdog logging.

  • CVE-2010-1073Mar 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the jEmbed-Embed Anything (com_jembed) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a summary action to index.php.

  • CVE-2010-1072Mar 23, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php in Sniggabo CMS 2.21 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

  • CVE-2010-1071Mar 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in profil.php in phpMDJ 1.0.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2010-1070Mar 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in ImagoScripts Deviant Art Clone allows remote attackers to execute arbitrary SQL commands via the seid parameter in a forums viewcat action.

  • CVE-2010-1069Mar 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in games/game.php in ProArcadeScript allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2010-1068Mar 23, 2010
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary web script or HTML via the (1) domainid or (2) classid parameter in a class action.

  • CVE-2010-1067Mar 23, 2010
    risk 0.03cvss —epss 0.02

    E-membres 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/bdEMembres.mdb.

  • CVE-2010-1066Mar 23, 2010
    risk 0.03cvss —epss 0.02

    AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for control/db_backup.php.

  • CVE-2010-1065Mar 23, 2010
    risk 0.03cvss —epss 0.02

    Lebisoft Ziyaretci Defteri 7.4 and 7.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/lebisoft.mdb.

  • CVE-2010-1064Mar 23, 2010
    risk 0.03cvss —epss 0.02

    Erolife AjxGaleri VT stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/ajxgaleri.mdb.

  • CVE-2010-1040Mar 23, 2010
    risk 0.00cvss —epss 0.01

    The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device support is enabled, allows remote attackers to bypass the "simple login" functionality via unknown vectors related to spoofing.

  • CVE-2009-4736Mar 23, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php in CommonSense CMS 5.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

  • CVE-2010-1063Mar 23, 2010
    risk 0.00cvss —epss 0.01

    Multiple directory traversal vulnerabilities in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1)…

  • CVE-2010-1062Mar 23, 2010
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter. NOTE: some of…

  • CVE-2010-1061Mar 23, 2010
    risk 0.00cvss —epss 0.01

    Multiple directory traversal vulnerabilities in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1) url/app/common.inc.php and (2)…

  • CVE-2010-1060Mar 23, 2010
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter.

  • CVE-2010-1059Mar 23, 2010
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter. NOTE: the…

  • CVE-2010-1058Mar 23, 2010
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter.

  • CVE-2010-1057Mar 23, 2010
    risk 0.03cvss —epss 0.02

    Multiple directory traversal vulnerabilities in Phpkobo AdFreely (aka Ad Board Script) 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a ..// (dot dot slash slash) in the LANG_CODE parameter to common.inc.php in…

  • CVE-2010-1056Mar 23, 2010
    risk 0.04cvss —epss 0.11

    Directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

  • CVE-2010-1055Mar 23, 2010
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in osDate 2.1.9 and 2.5.4, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the config[forum_installed] parameter to (1) forum/adminLogin.php…

  • CVE-2010-1054Mar 23, 2010
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in ParsCMS allow remote attackers to execute arbitrary SQL commands via the RP parameter to (1) fa_default.asp and (2) en_default.asp.

  • CVE-2010-1053Mar 23, 2010
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to (a) userlogin.php and (b) managerlogin.php. NOTE: some of…

  • CVE-2010-1052Mar 23, 2010
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) mday parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from…

  • CVE-2010-1051Mar 23, 2010
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) month parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2010-1050Mar 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in AudiStat 1.3 allows remote attackers to execute arbitrary SQL commands via the mday parameter.

  • CVE-2010-1049Mar 23, 2010
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Uiga Business Portal allow remote attackers to execute arbitrary SQL commands via the (1) noentryid parameter to blog/index.php and the (2) p parameter to index2.php.

  • CVE-2010-1048Mar 23, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in blog/index.php in Uiga Business Portal allows remote attackers to inject arbitrary web script or HTML via the textcomment parameter (aka the Comment Box) in a noentryid action. NOTE: some of these details are obtained from third party…

  • CVE-2010-1047Mar 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in MASA2EL Music City 1.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a singer action.

  • CVE-2010-1046Mar 23, 2010
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in index.php in Rostermain 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) userid (username) and (2) password parameters.

  • CVE-2010-1045Mar 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Productbook (com_productbook) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: some of these details are obtained from third party information.

  • CVE-2010-1044Mar 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpPort parameter.

  • CVE-2010-1043Mar 23, 2010
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in jaxCMS 1.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.

  • CVE-2010-1042Mar 23, 2010
    risk 0.04cvss —epss 0.10

    Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .AVI file. NOTE: the provenance of this information is unknown; the…

  • CVE-2010-1041Mar 23, 2010
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the single sign-on functionality in the Web Services implementation in IBM DB2 Content Manager (CM) Toolkit 8.3 before FP13 on z/OS and DB2 Information Integrator for Content 8.3 before FP13 has unknown impact and remote attack vectors.

  • CVE-2010-0163Mar 23, 2010
    risk 0.00cvss —epss 0.03

    Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a…

  • CVE-2010-0161Mar 23, 2010
    risk 0.00cvss —epss 0.02

    The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of service (heap memory…