NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 10950 | CVE-2011-4561 | Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php. NOTE: some of these details are obtained from third party information. | 2 | 4.3 | Medium | 2017-01-07 | 2011-12-19 | View | |
| 10949 | CVE-2011-4560 | Cross-site scripting (XSS) vulnerability in the Petition Node module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to signing a petition. | 2 | 3.5 | Low | 2017-01-07 | 2012-01-03 | View | |
| 10948 | CVE-2011-4559 | SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. | 2 | 7.5 | High | 2017-01-07 | 2011-11-29 | View | |
| 10947 | CVE-2011-4555 | One Click Orgs before 1.2.3 does not require unique e-mail addresses for user accounts, which allows remote authenticated users to cause a denial of service (login disruption) or spoof votes or comments by selecting a conflicting e-mail address. | 2 | 4 | Medium | 2017-01-07 | 2011-12-08 | View | |
| 10946 | CVE-2011-4554 | One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) " (double quote) and newline characters in an org name or (2) " (double quote) characters in an e-mail address, related to a "2nd Order SMTP Injection" issue. | 2 | 5.5 | Medium | 2017-01-07 | 2011-12-08 | View |
Page 15483 of 17672, showing 5 records out of 88360 total, starting on record 77411, ending on 77415