NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
11250  CVE-2011-4949  SQL injection vulnerability in phpgwapi/js/dhtmlxtree/samples/with_db/loaddetails.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-07  2012-12-17  View
11249  CVE-2011-4948  Directory traversal vulnerability in admin/remote.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in the type parameter.    Medium  2017-01-07  2012-09-03  View
11248  CVE-2011-4947  Cross-site request forgery (CSRF) vulnerability in e107_admin/users_extended.php in e107 before 0.7.26 allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences via the user_include parameter.    6.8  Medium  2017-01-07  2012-09-04  View
11247  CVE-2011-4946  SQL injection vulnerability in e107_admin/users_extended.php in e107 before 0.7.26 allows remote attackers to execute arbitrary SQL commands via the user_field parameter.    6.8  Medium  2017-01-07  2012-09-03  View
11246  CVE-2011-4945  PolicyKit 0.103 sets the AdminIdentities to "wheel" by default, which allows local users in the wheel group to gain root privileges without authentication.    6.9  Medium  2017-01-07  2012-12-18  View

Page 15423 of 17672, showing 5 records out of 88360 total, starting on record 77111, ending on 77115

Actions