NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11395 | CVE-2011-5135 | Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in DoceboLMS 4.0.4 and earlier allow remote authenticated users with admin or teacher privileges to execute arbitrary SQL commands via the (1) coursereportuiconfig[name] or (2) coursereportuiconfig[description] parameters to index.php. | 2 | 6 | Medium | 2017-01-07 | 2012-09-13 | View | |
| 11394 | CVE-2011-5134 | Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privileges to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. NOTE: some of these details are obtained from third party information. | 2 | 6 | Medium | 2017-01-07 | 2012-09-13 | View | |
| 11393 | CVE-2011-5133 | Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list." | 2 | 10 | High | 2017-01-07 | 2012-09-13 | View | |
| 11392 | CVE-2011-5132 | Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX." | 2 | 4.3 | Medium | 2017-01-07 | 2012-09-13 | View | |
| 11391 | CVE-2011-5131 | Cross-site request forgery (CSRF) vulnerability in global.php in MyBB before 1.6.5 allows remote attackers to hijack the authentication of a user for requests that change the user"s language via the language parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2012-09-13 | View |
Page 15394 of 17672, showing 5 records out of 88360 total, starting on record 76966, ending on 76970