NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
11515  CVE-2011-5259  SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.    6.8  Medium  2017-01-07  2013-02-13  View
11514  CVE-2011-5258  Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.6.11.2 allow remote attackers to inject arbitrary web script or HTML via the (1) uniqcode or (2) isAdmin parameter to index.php; or the (3) PATH_INFO to lib/controllers/centralcontroller.php.    4.3  Medium  2017-01-07  2013-02-13  View
11513  CVE-2011-5257  Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) twitter_id parameter related to the Twitter widget and (2) facebook_id parameter related to the Facebook widget.    4.3  Medium  2017-01-07  2013-02-13  View
11512  CVE-2011-5256  Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters.    2.6  Low  2017-01-07  2013-02-13  View
11511  CVE-2011-5255  Multiple cross-site scripting (XSS) vulnerabilities in admin/login in X3 CMS 0.4.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) username, or (3) password parameter.    4.3  Medium  2017-01-07  2013-01-31  View

Page 15370 of 17672, showing 5 records out of 88360 total, starting on record 76846, ending on 76850

Actions