267581
|
- |
|
citrix
|
xenserver
|
Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-0633
|
2010-03-18 13:00 |
2010-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267582
|
- |
|
joomlamo
|
com_cartweberp
|
Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to in…
|
CWE-22
Path Traversal
|
CVE-2010-0982
|
2010-03-18 03:44 |
2010-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267583
|
- |
|
dzcp
|
dev\!l\'z_clanportal
|
PHP remote file inclusion vulnerability in inc/config.php in deV!L`z Clanportal (DZCP) 1.5.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the …
|
CWE-94
Code Injection
|
CVE-2010-0966
|
2010-03-17 22:27 |
2010-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267584
|
- |
|
geekhelps
|
admp
|
SQL injection vulnerability in bannershow.php in Geekhelps ADMP 1.01 allows remote attackers to execute arbitrary SQL commands via the click parameter.
|
CWE-89
SQL Injection
|
CVE-2010-0968
|
2010-03-17 13:00 |
2010-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267585
|
- |
|
pordus
|
pd_portal
|
PD PORTAL 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-0977
|
2010-03-17 13:00 |
2010-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267586
|
- |
|
obsession-design
|
image-gallery
|
Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-0979
|
2010-03-17 13:00 |
2010-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267587
|
- |
|
robert_heel
|
cwt_resetbepassword
|
SQL injection vulnerability in the Reset backend password (cwt_resetbepassword) extension 1.20 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2009-4710
|
2010-03-17 13:00 |
2010-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267588
|
- |
|
alexandre_amaral
|
xoops_celepar
|
Cross-site scripting (XSS) vulnerability in the quiz module for XOOPS Celepar allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to cadastro_usuario.php.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4714
|
2010-03-17 13:00 |
2010-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267589
|
- |
|
gonafish
|
webstatcaffe
|
SQL injection vulnerability in visitorduration.php in Gonafish WebStatCaffe allows remote attackers to execute arbitrary SQL commands via the nodayshow parameter. NOTE: the provenance of this inform…
|
CWE-89
SQL Injection
|
CVE-2009-4718
|
2010-03-17 06:43 |
2010-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267590
|
- |
|
yuri_d\'elia
|
dl
|
Cross-site scripting (XSS) vulnerability in index.php in dl Download Ticket Service before 0.7 allows remote attackers to inject arbitrary web script or HTML via the t parameter, related to an invali…
|
CWE-79
Cross-site Scripting
|
CVE-2010-0963
|
2010-03-17 04:00 |
2010-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|