261611
|
- |
|
bitscripts
|
bits_video_script
|
Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allow remote attackers to execute arbitrary code by …
|
CWE-20
Improper Input Validation
|
CVE-2010-0366
|
2017-08-17 10:31 |
2010-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261612
|
- |
|
bitscripts
|
bits_video_script
|
Multiple PHP remote file inclusion vulnerabilities in BitScripts Bits Video Script 2.05 Gold Beta, and possibly 2.04, allow remote attackers to execute arbitrary PHP code via a URL in the rowptem[tem…
|
CWE-94
Code Injection
|
CVE-2010-0367
|
2017-08-17 10:31 |
2010-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261613
|
- |
|
hitmaaan
|
hitmaaan_gallery
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Hitmaaan Gallery 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gall and (2) levela parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2010-0371
|
2017-08-17 10:31 |
2010-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261614
|
- |
|
hong_chuyen
|
com_articlemanager
|
SQL injection vulnerability in the Articlemanager (com_articlemanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the artid parameter in a display action to i…
|
CWE-89
SQL Injection
|
CVE-2010-0372
|
2017-08-17 10:31 |
2010-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261615
|
- |
|
joomla
|
com_libros
|
SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.
|
CWE-89
SQL Injection
|
CVE-2010-0373
|
2017-08-17 10:31 |
2010-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261616
|
- |
|
codingfish
|
com_marketplace
|
Cross-site scripting (XSS) vulnerability in the Marketplace (com_marketplace) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the catid parameter in a sho…
|
CWE-79
Cross-site Scripting
|
CVE-2010-0374
|
2017-08-17 10:31 |
2010-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261617
|
- |
|
jce-tech
|
php_calendars_script
|
SQL injection vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenanc…
|
CWE-89
SQL Injection
|
CVE-2010-0375
|
2017-08-17 10:31 |
2010-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261618
|
- |
|
jce-tech
|
php_calendars_script
|
Cross-site scripting (XSS) vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to inject arbitrary web script or HTML via the cat parameter. N…
|
CWE-79
Cross-site Scripting
|
CVE-2010-0376
|
2017-08-17 10:31 |
2010-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261619
|
- |
|
sun
|
java_system_web_server
|
Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a denial of service (daemon crash) and possibl…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-0387
|
2017-08-17 10:31 |
2010-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261620
|
- |
|
sun
|
java_system_web_server
|
Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash) and possibly have u…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2010-0388
|
2017-08-17 10:31 |
2010-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|