266111
|
- |
|
alex_kellner
|
powermail
|
Unspecified vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to bypass validation have an unspecified impact by "[injecting] arbitrary values into validate…
|
NVD-CWE-noinfo
|
CVE-2010-3687
|
2010-09-30 13:00 |
2010-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266112
|
- |
|
vmware
|
workstation player
|
The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3277
|
2010-09-29 13:00 |
2010-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266113
|
- |
|
alex_kellner
|
powermail
|
Cross-site scripting (XSS) vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3605
|
2010-09-28 05:38 |
2010-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266114
|
- |
|
salvo_g._tomaselli
|
weborf
|
Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI.
|
CWE-22
Path Traversal
|
CVE-2010-3306
|
2010-09-27 13:00 |
2010-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266115
|
- |
|
invisionpower
|
ibphotohost
|
SQL injection vulnerability in index.php in ibPhotohost 1.1.2 allows remote attackers to execute arbitrary SQL commands via the img parameter.
|
CWE-89
SQL Injection
|
CVE-2010-3601
|
2010-09-27 13:00 |
2010-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266116
|
- |
|
alex_kellner
|
powermail
|
SQL injection vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2010-3604
|
2010-09-27 13:00 |
2010-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266117
|
- |
|
wire_plastic_design
|
wpquiz
|
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) password (pw) parameters to (a) admin.php or (b) user.php.
|
CWE-89
SQL Injection
|
CVE-2010-3608
|
2010-09-27 13:00 |
2010-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266118
|
- |
|
cisco
|
ios
|
Memory leak in the SSL VPN feature in Cisco IOS 12.4, 15.0, and 15.1, when HTTP port redirection is enabled, allows remote attackers to cause a denial of service (memory consumption) by improperly di…
|
CWE-399
Resource Management Errors
|
CVE-2010-2836
|
2010-09-25 03:12 |
2010-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266119
|
- |
|
cisco
|
ios ios_xe unified_communications_manager
|
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.0 before 7…
|
NVD-CWE-noinfo
|
CVE-2010-2835
|
2010-09-25 03:04 |
2010-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266120
|
- |
|
cisco
|
ios ios_xe
|
Unspecified vulnerability in the NAT for H.323 implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1 allows remote attackers to cause a denial of service (device reload) via transit tra…
|
NVD-CWE-noinfo
|
CVE-2010-2832
|
2010-09-25 02:40 |
2010-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|