NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
10031  CVE-2011-3379  The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.    7.5  High  2017-01-07  2012-07-03  View
10543  CVE-2011-3989  SQL injection vulnerability in DBD::mysqlPP 0.04 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.    7.5  High  2017-01-07  2012-03-12  View
11311  CVE-2011-5051  Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension using (1) uploadify/upload_admin_avatar.php or (2) uploadify/upload_profile_avatar.php, then accessing it via a direct request to the file in an unspecified directory inside the webroot.    7.5  High  2017-01-07  2012-01-05  View
77871  CVE-2001-0398  The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT! to misrepresent the attachment"s type with a different icon.    7.5  High  2017-01-05  2008-09-05  View
13103  CVE-2010-1583  SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN) Framework 1.5, as used in TaskFreak! before 0.6.3, allows remote attackers to execute arbitrary SQL commands via the username field in a login action.    7.5  High  2017-01-18  2010-05-11  View

Page 2468 of 17672, showing 5 records out of 88360 total, starting on record 12336, ending on 12340

Actions