274881
|
- |
|
joomlanook
|
com_hsconfig
|
Directory traversal vulnerability in the Highslide JS (com_hsconfig) component 1.5 and 2.0.9 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter…
|
CWE-22
Path Traversal
|
CVE-2010-1314
|
2010-04-9 13:00 |
2010-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274882
|
- |
|
mahara
|
mahara
|
SQL injection vulnerability in lib/user.php in mahara 1.0.4 allows remote attackers to execute arbitrary SQL commands via a username.
|
CWE-89
SQL Injection
|
CVE-2010-0400
|
2010-04-8 22:25 |
2010-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274883
|
- |
|
decryptweb
|
com_dwgraphs
|
Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequence…
|
CWE-22
Path Traversal
|
CVE-2010-1302
|
2010-04-8 13:00 |
2010-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274884
|
- |
|
ermenegildo_fiorito
|
irmin_cms
|
Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, when register_globals is enabled, allows remote attackers to include and execute…
|
CWE-22
Path Traversal
|
CVE-2008-7254
|
2010-04-8 13:00 |
2010-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274885
|
- |
|
ekith
|
com_dcs_flashgames
|
SQL injection vulnerability in Adam Corley dcsFlashGames (com_dcs_flashgames) allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2010-1265
|
2010-04-7 13:00 |
2010-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274886
|
- |
|
kjetiltroan
|
webmaid_cms
|
Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the com parameter to (1) cContac…
|
CWE-22
Path Traversal
|
CVE-2010-1267
|
2010-04-7 13:00 |
2010-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274887
|
- |
|
bbsxp
|
bbsxp
|
Multiple cross-site scripting (XSS) vulnerabilities in BBSXP 2008 SP2 allow remote attackers to inject arbitrary web script or HTML via the URI in a request to (1) AddPost.asp, (2) AddTopic.asp, (3) …
|
CWE-79
Cross-site Scripting
|
CVE-2010-1276
|
2010-04-7 13:00 |
2010-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274888
|
- |
|
pulsecms
|
pulse_cms
|
Directory traversal vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to read arbitrary files via directory traversal sequences in the f parameter. NOTE: the provenance of this in…
|
CWE-22
Path Traversal
|
CVE-2010-1298
|
2010-04-7 13:00 |
2010-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274889
|
- |
|
pulsecms
|
pulse_cms
|
per: http://secunia.com/advisories/38650
'2) Input passed via the "f" parameter to view.php is not properly sanitised before being used to read files. This can be exploited to disclose the content…
|
CWE-22
Path Traversal
|
CVE-2010-1298
|
2010-04-7 13:00 |
2010-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274890
|
- |
|
novell
|
netware_ftp_server netware
|
NWFTPD.nlm before 5.08.06 in the FTP server in Novell NetWare does not properly handle partial matches for container names in the FTPREST.TXT file, which allows remote attackers to bypass intended ac…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6735
|
2010-04-6 23:22 |
2010-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|