270101
|
- |
|
entrylevelcms
|
el_cms
|
Cross-site scripting (XSS) vulnerability in index.php in Entry Level CMS (EL CMS) allows remote attackers to inject arbitrary web script or HTML via the subj parameter, which is not properly handled …
|
CWE-79
Cross-site Scripting
|
CVE-2010-1076
|
2010-03-25 03:25 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270102
|
- |
|
proarcadescript
|
proarcadescript
|
SQL injection vulnerability in games/game.php in ProArcadeScript allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-1069
|
2010-03-25 02:25 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270103
|
- |
|
phpkobo
|
free_real_estate_contact_form_script
|
Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitr…
|
CWE-22
Path Traversal
|
CVE-2010-1062
|
2010-03-24 23:40 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270104
|
- |
|
phpkobo
|
short_url
|
Multiple directory traversal vulnerabilities in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal …
|
CWE-22
Path Traversal
|
CVE-2010-1061
|
2010-03-24 23:30 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270105
|
- |
|
tejimaya
|
openpne
|
The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device support is enabled, allows remote attackers to bypas…
|
CWE-287
Improper Authentication
|
CVE-2010-1040
|
2010-03-24 13:00 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270106
|
- |
|
phpkobo
|
address_book_script
|
Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local fi…
|
CWE-22
Path Traversal
|
CVE-2010-1059
|
2010-03-24 13:00 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270107
|
- |
|
phpkobo
|
short_url
|
Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a …
|
CWE-22
Path Traversal
|
CVE-2010-1060
|
2010-03-24 13:00 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270108
|
- |
|
phpkobo
|
free_real_estate_contact_form_script
|
Multiple directory traversal vulnerabilities in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via …
|
CWE-22
Path Traversal
|
CVE-2010-1063
|
2010-03-24 13:00 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270109
|
- |
|
entrylevelcms
|
el_cms
|
SQL injection vulnerability in index.php in Entry Level CMS (EL CMS) allows remote attackers to execute arbitrary SQL commands via the subj parameter.
|
CWE-89
SQL Injection
|
CVE-2010-1075
|
2010-03-24 13:00 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270110
|
- |
|
ryan_marshall
|
rostermain
|
Multiple SQL injection vulnerabilities in index.php in Rostermain 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) userid (username) and (2) password parameters.
|
CWE-89
SQL Injection
|
CVE-2010-1046
|
2010-03-23 22:53 |
2010-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|