267891
|
- |
|
springsource
|
application_management_suite hyperic_hq tc_server
|
Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Management Suite (AMS) before 2.0.0.SR4, Hyperic HQ Open Source before 4.2.x, Hyperic H…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2907
|
2010-03-25 13:00 |
2010-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267892
|
- |
|
springsource
|
application_management_suite hyperic_hq tc_server
|
Per: http://www.springsource.com/security/cve-2009-2907
'Mitigation:
* Hyperic HQ Open Source users should upgrade to Hyperic HQ 4.2.x
* Hyperic HQ 4.0 Enterprise users should upgra…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2907
|
2010-03-25 13:00 |
2010-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267893
|
- |
|
openinferno
|
oi.blogs
|
Multiple directory traversal vulnerabilities in OI.Blogs 1.0.0, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via directory traversal sequences in the (1) theme pa…
|
CWE-22
Path Traversal
|
CVE-2010-1082
|
2010-03-25 04:52 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267894
|
- |
|
corejoomla
|
com_communitypolls
|
Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote attackers to read arbitrary files via a .. (dot dot…
|
CWE-22
Path Traversal
|
CVE-2010-1081
|
2010-03-25 04:30 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267895
|
- |
|
sawmill
|
sawmill
|
Cross-site scripting (XSS) vulnerability in Sawmill before 7.2.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-1079
|
2010-03-25 04:12 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267896
|
- |
|
entrylevelcms
|
el_cms
|
Cross-site scripting (XSS) vulnerability in index.php in Entry Level CMS (EL CMS) allows remote attackers to inject arbitrary web script or HTML via the subj parameter, which is not properly handled …
|
CWE-79
Cross-site Scripting
|
CVE-2010-1076
|
2010-03-25 03:25 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267897
|
- |
|
proarcadescript
|
proarcadescript
|
SQL injection vulnerability in games/game.php in ProArcadeScript allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-1069
|
2010-03-25 02:25 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267898
|
- |
|
phpkobo
|
free_real_estate_contact_form_script
|
Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitr…
|
CWE-22
Path Traversal
|
CVE-2010-1062
|
2010-03-24 23:40 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267899
|
- |
|
phpkobo
|
short_url
|
Multiple directory traversal vulnerabilities in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal …
|
CWE-22
Path Traversal
|
CVE-2010-1061
|
2010-03-24 23:30 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267900
|
- |
|
tejimaya
|
openpne
|
The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device support is enabled, allows remote attackers to bypas…
|
CWE-287
Improper Authentication
|
CVE-2010-1040
|
2010-03-24 13:00 |
2010-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|