NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11515 | CVE-2011-5259 | SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2013-02-13 | View | |
| 11514 | CVE-2011-5258 | Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.6.11.2 allow remote attackers to inject arbitrary web script or HTML via the (1) uniqcode or (2) isAdmin parameter to index.php; or the (3) PATH_INFO to lib/controllers/centralcontroller.php. | 2 | 4.3 | Medium | 2017-01-07 | 2013-02-13 | View | |
| 11513 | CVE-2011-5257 | Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) twitter_id parameter related to the Twitter widget and (2) facebook_id parameter related to the Facebook widget. | 2 | 4.3 | Medium | 2017-01-07 | 2013-02-13 | View | |
| 11512 | CVE-2011-5256 | Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters. | 2 | 2.6 | Low | 2017-01-07 | 2013-02-13 | View | |
| 11511 | CVE-2011-5255 | Multiple cross-site scripting (XSS) vulnerabilities in admin/login in X3 CMS 0.4.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) username, or (3) password parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2013-01-31 | View |
Page 15370 of 17672, showing 5 records out of 88360 total, starting on record 76846, ending on 76850