NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11161 | CVE-2011-4823 | Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract parameter in a results action and (2) imm parameter in a show action to index.php. | 2 | 7.5 | High | 2017-01-07 | 2012-02-09 | View | |
| 11162 | CVE-2011-4824 | SQL injection vulnerability in auth_login.php in Cacti before 0.8.7h allows remote attackers to execute arbitrary SQL commands via the login_username parameter. | 2 | 7.5 | High | 2017-01-07 | 2012-10-27 | View | |
| 11163 | CVE-2011-4825 | Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters. | 2 | 7.5 | High | 2017-01-07 | 2011-12-15 | View | |
| 11164 | CVE-2011-4826 | SQL injection vulnerability in session.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to process.php. NOTE: some of these details are obtained from third party information. | 2 | 6.8 | Medium | 2017-01-07 | 2012-02-09 | View | |
| 11165 | CVE-2011-4827 | Multiple cross-site scripting (XSS) vulnerabilities in AutoSec Tools V-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) p parameter to redirect.php and (2) box parameter to includes/TrueColorPicker/index.php, which is not properly handled in includes/TrueColorPicker/class.TrueColorPicker.php. | 2 | 4.3 | Medium | 2017-01-07 | 2012-02-09 | View |
Page 2233 of 17672, showing 5 records out of 88360 total, starting on record 11161, ending on 11165