266661
|
- |
|
xmlswf
|
com_picsell
|
Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dflink parameter in a prevsell dwnfr…
|
CWE-22
Path Traversal
|
CVE-2010-3203
|
2010-09-6 13:00 |
2010-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266662
|
- |
|
common1
|
moobbs
|
Cross-site scripting (XSS) vulnerability in Free CGI Moo moobbs before 1.03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2364
|
2010-09-1 07:00 |
2010-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266663
|
- |
|
common1
|
moobbs2
|
Cross-site scripting (XSS) vulnerability in Free CGI Moo moobbs2 before 1.03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2365
|
2010-09-1 07:00 |
2010-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266664
|
- |
|
php
|
php
|
The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended ac…
|
CWE-20
Improper Input Validation
|
CVE-2010-1129
|
2010-08-31 14:42 |
2010-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266665
|
- |
|
simone_rota
|
slim_simple_login_manager
|
The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the cu…
|
CWE-16
Configuration
|
CVE-2010-2945
|
2010-08-31 13:00 |
2010-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266666
|
- |
|
adobe
|
extension_manager_cs5
|
Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan …
|
NVD-CWE-Other
|
CVE-2010-3154
|
2010-08-30 23:54 |
2010-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266667
|
- |
|
wyse
|
thinos_hf
|
Buffer overflow in Wyse ThinOS HF 4.4.079i, and possibly other versions before ThinOS 6.5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3031
|
2010-08-30 13:00 |
2010-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266668
|
- |
|
viewvc
|
viewvc
|
lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted…
|
NVD-CWE-noinfo
|
CVE-2008-4325
|
2010-08-30 13:00 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266669
|
- |
|
blackboard
|
blackboard_learning_and_community_post_systems
|
Multiple cross-site scripting (XSS) vulnerabilities in messaging/course/composeMessage.jsp in BlackBoard Learning System 6.3.1.593 and earlier in BlackBoard Academic Suite allow remote attackers to i…
|
CWE-79
Cross-site Scripting
|
CVE-2007-5227
|
2010-08-30 13:00 |
2007-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266670
|
- |
|
uninet
|
statsplus
|
Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to s…
|
CWE-79
Cross-site Scripting
|
CVE-2002-2330
|
2010-08-30 13:00 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|