NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 10946 | CVE-2011-4554 | One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) " (double quote) and newline characters in an org name or (2) " (double quote) characters in an e-mail address, related to a "2nd Order SMTP Injection" issue. | 2 | 5.5 | Medium | 2017-01-07 | 2011-12-08 | View | |
| 10947 | CVE-2011-4555 | One Click Orgs before 1.2.3 does not require unique e-mail addresses for user accounts, which allows remote authenticated users to cause a denial of service (login disruption) or spoof votes or comments by selecting a conflicting e-mail address. | 2 | 4 | Medium | 2017-01-07 | 2011-12-08 | View | |
| 10948 | CVE-2011-4559 | SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. | 2 | 7.5 | High | 2017-01-07 | 2011-11-29 | View | |
| 10949 | CVE-2011-4560 | Cross-site scripting (XSS) vulnerability in the Petition Node module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to signing a petition. | 2 | 3.5 | Low | 2017-01-07 | 2012-01-03 | View | |
| 10950 | CVE-2011-4561 | Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php. NOTE: some of these details are obtained from third party information. | 2 | 4.3 | Medium | 2017-01-07 | 2011-12-19 | View |
Page 2190 of 17672, showing 5 records out of 88360 total, starting on record 10946, ending on 10950