NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
11400  CVE-2011-5140  Multiple SQL injection vulnerabilities in the blog module 1.0 for DiY-CMS allow remote attackers to execute arbitrary SQL commands via the (1) start parameter to (a) tags.php, (b) list.php, (c) index.php, (d) main_index.php, (e) viewpost.php, (f) archive.php, (g) control/approve_comments.php, (h) control/approve_posts.php, and (i) control/viewcat.php; and the (2) month and (3) year parameters to archive.php.    7.5  High  2017-01-07  2012-09-03  View
11399  CVE-2011-5139  SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-07  2012-09-05  View
11398  CVE-2011-5138  Cross-site scripting (XSS) vulnerability in member.php in tForum b0.915 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a viewprofile action.    4.3  Medium  2017-01-07  2012-09-04  View
11397  CVE-2011-5137  Multiple SQL injection vulnerabilities in tForum b0.915 allow remote attackers to execute arbitrary SQL commands via the (1) TopicID parameter to viewtopic.php, the (2) BoardID parameter to viewboard.php, or (3) CatID parameter to viewcat.php.    7.5  High  2017-01-07  2012-09-05  View
11396  CVE-2011-5136  showImg.php in EPractize Labs Subscription Manager, possibly 1.0, allows remote attackers to overwrite arbitrary files via the db parameter.    6.4  Medium  2017-01-07  2012-09-13  View

Page 15393 of 17672, showing 5 records out of 88360 total, starting on record 76961, ending on 76965

Actions