NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
11395  CVE-2011-5135  Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in DoceboLMS 4.0.4 and earlier allow remote authenticated users with admin or teacher privileges to execute arbitrary SQL commands via the (1) coursereportuiconfig[name] or (2) coursereportuiconfig[description] parameters to index.php.    Medium  2017-01-07  2012-09-13  View
11394  CVE-2011-5134  Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privileges to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. NOTE: some of these details are obtained from third party information.    Medium  2017-01-07  2012-09-13  View
11393  CVE-2011-5133  Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list."    10  High  2017-01-07  2012-09-13  View
11392  CVE-2011-5132  Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX."    4.3  Medium  2017-01-07  2012-09-13  View
11391  CVE-2011-5131  Cross-site request forgery (CSRF) vulnerability in global.php in MyBB before 1.6.5 allows remote attackers to hijack the authentication of a user for requests that change the user"s language via the language parameter.    6.8  Medium  2017-01-07  2012-09-13  View

Page 15394 of 17672, showing 5 records out of 88360 total, starting on record 76966, ending on 76970

Actions