270541
|
- |
|
entrylevelcms
|
el_cms
|
SQL injection vulnerability in index.php in Entry Level CMS (EL CMS) allows remote attackers to execute arbitrary SQL commands via the subj parameter.
|
CWE-89
SQL Injection
|
CVE-2010-1075
|
2010-03-24 13:00 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270542
|
- |
|
ryan_marshall
|
rostermain
|
Multiple SQL injection vulnerabilities in index.php in Rostermain 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) userid (username) and (2) password parameters.
|
CWE-89
SQL Injection
|
CVE-2010-1046
|
2010-03-23 22:53 |
2010-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270543
|
- |
|
jaxcms
|
jaxcms
|
Directory traversal vulnerability in index.php in jaxCMS 1.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.
|
CWE-22
Path Traversal
|
CVE-2010-1043
|
2010-03-23 13:00 |
2010-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270544
|
- |
|
design-cars
|
com_productbook
|
SQL injection vulnerability in the Productbook (com_productbook) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index…
|
CWE-89
SQL Injection
|
CVE-2010-1045
|
2010-03-23 13:00 |
2010-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270545
|
- |
|
uiga
|
business_portal
|
Cross-site scripting (XSS) vulnerability in blog/index.php in Uiga Business Portal allows remote attackers to inject arbitrary web script or HTML via the textcomment parameter (aka the Comment Box) i…
|
CWE-79
Cross-site Scripting
|
CVE-2010-1048
|
2010-03-23 13:00 |
2010-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270546
|
- |
|
alexandre_dubus
|
audistat
|
SQL injection vulnerability in index.php in AudiStat 1.3 allows remote attackers to execute arbitrary SQL commands via the mday parameter.
|
CWE-89
SQL Injection
|
CVE-2010-1050
|
2010-03-23 13:00 |
2010-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270547
|
- |
|
alexandre_dubus
|
audistat
|
Multiple SQL injection vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) month parameters. NOTE: the provenance of this i…
|
CWE-89
SQL Injection
|
CVE-2010-1051
|
2010-03-23 13:00 |
2010-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270548
|
- |
|
alexandre_dubus
|
audistat
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) mday parameters. NOTE: the pro…
|
CWE-79
Cross-site Scripting
|
CVE-2010-1052
|
2010-03-23 13:00 |
2010-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270549
|
- |
|
marcus_krause
|
t3sec_saltedpw
|
The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2010-1022
|
2010-03-23 02:17 |
2010-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270550
|
- |
|
sk-typo3
|
sk_simplegallery
|
Cross-site scripting (XSS) vulnerability in the Simple Gallery (sk_simplegallery) extension 0.0.9 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified …
|
CWE-79
Cross-site Scripting
|
CVE-2010-1020
|
2010-03-23 01:58 |
2010-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|