267011
|
- |
|
joomla
|
com_sef
|
PHP remote file inclusion vulnerability in the SEF404x (com_sef) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig.absolute.path parameter to inde…
|
CWE-94
Code Injection
|
CVE-2010-2681
|
2010-07-12 22:27 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267012
|
- |
|
customerparadigm
|
pagedirector_cms
|
SQL injection vulnerability in result.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitrary SQL commands via the sub_catid parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2683
|
2010-07-12 22:27 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267013
|
- |
|
jooforge
|
com_gamesbox
|
SQL injection vulnerability in the JOOFORGE Gamesbox (com_gamesbox) component 1.0.2, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter i…
|
CWE-89
SQL Injection
|
CVE-2010-2690
|
2010-07-12 22:27 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267014
|
- |
|
esoftpro
|
online_contact_manager
|
Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) showGroup parameter…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4926
|
2010-07-12 22:27 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267015
|
- |
|
esoftpro
|
online_photo_pro
|
Cross-site scripting (XSS) vulnerability in index.php in Online Photo Pro 2.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4934
|
2010-07-12 22:27 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267016
|
- |
|
ez
|
ez_publish
|
Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to inject arbitrary web script or HTML via the subTreeItem parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2671
|
2010-07-9 13:00 |
2010-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267017
|
- |
|
ez
|
ez_publish
|
Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) SectionID and (2) SearchTimestamp parameters to the searc…
|
CWE-89
SQL Injection
|
CVE-2010-2672
|
2010-07-9 13:00 |
2010-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267018
|
- |
|
devana
|
devana
|
SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2673
|
2010-07-9 13:00 |
2010-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267019
|
- |
|
mahara
|
mahara
|
Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 has improper configuration options for authentication plugins associated with logins that use the single sign-on (SSO) functionality, …
|
CWE-287
Improper Authentication
|
CVE-2010-1670
|
2010-07-7 13:00 |
2010-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267020
|
- |
|
htmlpurifier mahara
|
htmlpurifier mahara
|
Cross-site scripting (XSS) vulnerability in HTML Purifier before 4.1.1, as used in Mahara and other products, when the browser is Internet Explorer, allows remote attackers to inject arbitrary web sc…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2479
|
2010-07-7 13:00 |
2010-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|