NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 13795 | CVE-2010-2317 | Multiple SQL injection vulnerabilities in WmsCms 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) search, (2) sbr, (3) pid, (4) sbl, and (5) FilePath parameters to default.asp; and the (6) sbr, (7) pr, and (8) psPrice parameters to printpage.asp. | 2 | 7.5 | High | 2017-01-18 | 2010-06-18 | View | |
| 13794 | CVE-2010-2316 | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) sbr, (3) p, and (4) sbl parameters, different vectors than CVE-2007-3137. | 2 | 4.3 | Medium | 2017-01-18 | 2010-06-18 | View | |
| 13793 | CVE-2010-2315 | PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cat parameter. | 2 | 7.5 | High | 2017-01-18 | 2013-09-03 | View | |
| 13792 | CVE-2010-2314 | PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PLUGINS parameter. NOTE: some of these details are obtained from third party information. | 2 | 6.8 | Medium | 2017-01-18 | 2010-06-18 | View | |
| 13791 | CVE-2010-2313 | Directory traversal vulnerability in index.php in Anodyne Productions SIMM Management System (SMS) 2.6.10, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter to index.php. NOTE: some of these details are obtained from third party information. | 2 | 6.8 | Medium | 2017-01-18 | 2010-06-18 | View |
Page 14914 of 17672, showing 5 records out of 88360 total, starting on record 74566, ending on 74570