NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11526 | CVE-2011-5272 | SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the vps_note parameter to dtcadmin/logPushlet.php. NOTE: this issue was originally part of CVE-2011-3197, but that ID was SPLIT due to different researchers. | 2 | 6.5 | Medium | 2017-01-07 | 2014-03-24 | View | |
| 11527 | CVE-2011-5273 | Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the pkg parameter in a do_install action to dtc/. | 2 | 6.5 | Medium | 2017-01-07 | 2014-03-21 | View | |
| 11528 | CVE-2011-5274 | The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote attackers to execute arbitrary commands via shell metacharacters in the dtcpkg_directory parameter in a do_install action to dtc/. | 2 | 7.5 | High | 2017-01-07 | 2014-03-24 | View | |
| 11529 | CVE-2011-5275 | The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc user, which makes it easier for context-dependent users to gain privileges. | 2 | 7.5 | High | 2017-01-07 | 2014-03-21 | View | |
| 11530 | CVE-2011-5276 | SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote authenticated users to execute arbitrary SQL commands via the database_name parameter. | 2 | 6.5 | Medium | 2017-01-07 | 2014-03-21 | View |
Page 2306 of 17672, showing 5 records out of 88360 total, starting on record 11526, ending on 11530