NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11165 | CVE-2011-4827 | Multiple cross-site scripting (XSS) vulnerabilities in AutoSec Tools V-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) p parameter to redirect.php and (2) box parameter to includes/TrueColorPicker/index.php, which is not properly handled in includes/TrueColorPicker/class.TrueColorPicker.php. | 2 | 4.3 | Medium | 2017-01-07 | 2012-02-09 | View | |
| 11164 | CVE-2011-4826 | SQL injection vulnerability in session.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to process.php. NOTE: some of these details are obtained from third party information. | 2 | 6.8 | Medium | 2017-01-07 | 2012-02-09 | View | |
| 11163 | CVE-2011-4825 | Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters. | 2 | 7.5 | High | 2017-01-07 | 2011-12-15 | View | |
| 11162 | CVE-2011-4824 | SQL injection vulnerability in auth_login.php in Cacti before 0.8.7h allows remote attackers to execute arbitrary SQL commands via the login_username parameter. | 2 | 7.5 | High | 2017-01-07 | 2012-10-27 | View | |
| 11161 | CVE-2011-4823 | Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract parameter in a results action and (2) imm parameter in a show action to index.php. | 2 | 7.5 | High | 2017-01-07 | 2012-02-09 | View |
Page 15440 of 17672, showing 5 records out of 88360 total, starting on record 77196, ending on 77200