NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11171 | CVE-2011-4833 | Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0beta1 allow remote attackers to execute arbitrary SQL commands via the (1) where and (2) order parameters in a get_full_list action to index.php. | 2 | 7.5 | High | 2017-01-07 | 2012-02-09 | View | |
| 11172 | CVE-2011-4834 | The GetInstalledPackages function in the configuration tool in HP Application Lifestyle Management (ALM) 11 on AIX, HP-UX, and Solaris allows local users to gain privileges via (1) a Trojan horse /tmp/tmp.txt FIFO or (2) a symlink attack on /tmp/tmp.txt. | 2 | 4.6 | Medium | 2017-01-07 | 2011-12-15 | View | |
| 11173 | CVE-2011-4835 | Directory traversal vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to access arbitrary files via unspecified vectors. | 2 | 7.5 | High | 2017-01-07 | 2011-12-15 | View | |
| 11174 | CVE-2011-4836 | Cross-site scripting (XSS) vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to inject arbitrary web script or HTML via a request for a crafted URI. | 2 | 4.3 | Medium | 2017-01-07 | 2011-12-15 | View | |
| 11175 | CVE-2011-4837 | Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authentication of admins for requests that execute arbitrary programs. | 2 | 6.8 | Medium | 2017-01-07 | 2011-12-15 | View |
Page 2235 of 17672, showing 5 records out of 88360 total, starting on record 11171, ending on 11175