268071
|
- |
|
argosoft
|
argosoft_mail_server
|
ArGoSoft Mail Server 1.8.1.7 and earlier allows a webmail user to cause a denial of service (CPU consumption) by forwarding the email to the user while autoresponse is enabled, which creates an infin…
|
NVD-CWE-Other
|
CVE-2002-1005
|
2013-10-1 10:22 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268072
|
- |
|
mms.pipp
|
com_mmsblog
|
Directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot do…
|
CWE-22
Path Traversal
|
CVE-2010-1491
|
2013-09-13 15:31 |
2010-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268073
|
- |
|
mediawiki
|
mediawiki
|
thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-1190
|
2013-09-13 15:30 |
2010-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268074
|
- |
|
linkorcms
|
linkorcms
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in LinkorCMS 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the searchstr parameter in a search…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3192
|
2013-09-13 15:22 |
2009-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268075
|
- |
|
ewire
|
payment_client
|
The ewirePC_Decrypt function in ewirepcfunctions.php in eWire Payment Client (ePC) 1.60 and 1.70 allows remote attackers to execute arbitrary commands via shell metacharacters in the paymentinfo para…
|
CWE-20
Improper Input Validation
|
CVE-2007-4925
|
2013-09-13 14:43 |
2007-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268076
|
- |
|
uiga
|
business_portal
|
Multiple SQL injection vulnerabilities in Uiga Business Portal allow remote attackers to execute arbitrary SQL commands via the (1) noentryid parameter to blog/index.php and the (2) p parameter to in…
|
CWE-89
SQL Injection
|
CVE-2010-1049
|
2013-09-12 15:08 |
2010-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268077
|
- |
|
openedit_inc
|
openedit
|
Cross-site scripting (XSS) vulnerability in store/search/results.html in OpenEdit 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) oe-action and (2) page par…
|
NVD-CWE-Other
|
CVE-2005-4476
|
2013-09-12 13:48 |
2005-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268078
|
- |
|
ibm
|
db2
|
IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.
|
NVD-CWE-noinfo
|
CVE-2009-3473
|
2013-09-11 14:59 |
2009-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268079
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Directory traversal vulnerability in AFP Server in Apple Mac OS X before 10.6.3 allows remote attackers to list a share root's parent directory, and read and modify files in that directory, via unspe…
|
CWE-22
Path Traversal
|
CVE-2010-0533
|
2013-09-11 02:18 |
2010-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268080
|
- |
|
ternaria
|
com_vjdeo
|
Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.…
|
CWE-22
Path Traversal
|
CVE-2010-1354
|
2013-09-9 14:58 |
2010-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|