NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
7801 | CVE-2011-0771 | The Janrain Engage (formerly RPX) module 6.x-1.3 for Drupal does not validate the file for a profile image, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks and possibly execute arbitrary PHP code by causing a crafted avatar to be downloaded from an external login provider site. | 2 | 6.8 | Medium | 2017-01-07 | 2012-07-26 | View | |
7802 | CVE-2011-0772 | Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow remote attackers to inject arbitrary web script or HTML via the (1) color parameter to includes/blogroll.php or (2) src parameter to includes/timwrapper.php. | 2 | 4.3 | Medium | 2017-01-07 | 2011-09-21 | View | |
7803 | CVE-2011-0773 | Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the image parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2011-09-21 | View | |
7804 | CVE-2011-0774 | PivotX before 2.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) includes/ping.php and (2) includes/spamping.php, which reveals the installation path in an error message. | 2 | 5 | Medium | 2017-01-07 | 2011-02-22 | View | |
7805 | CVE-2011-0775 | pivotx/modules/module_image.php in PivotX 2.2.2 allows remote attackers to obtain sensitive information via a non-existent file in the image parameter, which reveals the installation path in an error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 5 | Medium | 2017-01-07 | 2011-02-22 | View |
Page 1561 of 17672, showing 5 records out of 88360 total, starting on record 7801, ending on 7805