267811
|
- |
|
decryptweb
|
com_dwgraphs
|
Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequence…
|
CWE-22
Path Traversal
|
CVE-2010-1302
|
2010-04-8 13:00 |
2010-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267812
|
- |
|
ermenegildo_fiorito
|
irmin_cms
|
Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, when register_globals is enabled, allows remote attackers to include and execute…
|
CWE-22
Path Traversal
|
CVE-2008-7254
|
2010-04-8 13:00 |
2010-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267813
|
- |
|
ekith
|
com_dcs_flashgames
|
SQL injection vulnerability in Adam Corley dcsFlashGames (com_dcs_flashgames) allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2010-1265
|
2010-04-7 13:00 |
2010-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267814
|
- |
|
kjetiltroan
|
webmaid_cms
|
Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the com parameter to (1) cContac…
|
CWE-22
Path Traversal
|
CVE-2010-1267
|
2010-04-7 13:00 |
2010-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267815
|
- |
|
bbsxp
|
bbsxp
|
Multiple cross-site scripting (XSS) vulnerabilities in BBSXP 2008 SP2 allow remote attackers to inject arbitrary web script or HTML via the URI in a request to (1) AddPost.asp, (2) AddTopic.asp, (3) …
|
CWE-79
Cross-site Scripting
|
CVE-2010-1276
|
2010-04-7 13:00 |
2010-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267816
|
- |
|
pulsecms
|
pulse_cms
|
Directory traversal vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to read arbitrary files via directory traversal sequences in the f parameter. NOTE: the provenance of this in…
|
CWE-22
Path Traversal
|
CVE-2010-1298
|
2010-04-7 13:00 |
2010-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267817
|
- |
|
pulsecms
|
pulse_cms
|
per: http://secunia.com/advisories/38650
'2) Input passed via the "f" parameter to view.php is not properly sanitised before being used to read files. This can be exploited to disclose the content…
|
CWE-22
Path Traversal
|
CVE-2010-1298
|
2010-04-7 13:00 |
2010-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267818
|
- |
|
novell
|
netware_ftp_server netware
|
NWFTPD.nlm before 5.08.06 in the FTP server in Novell NetWare does not properly handle partial matches for container names in the FTPREST.TXT file, which allows remote attackers to bypass intended ac…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6735
|
2010-04-6 23:22 |
2010-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267819
|
- |
|
foxitsoftware
|
foxit_reader
|
Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and (2) execute arbitrary programs embedded in a PDF …
|
CWE-94
Code Injection
|
CVE-2010-1239
|
2010-04-6 13:00 |
2010-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267820
|
- |
|
novell
|
netware_ftp_server netware
|
NWFTPD.nlm before 5.08.07 in the FTP server in Novell NetWare 6.5 SP7 does not properly implement the FTPREST.TXT NOREMOTE restriction, which allows remote authenticated users to access directories o…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6734
|
2010-04-6 13:00 |
2010-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|