NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 12641 | CVE-2010-1107 | Cross-site scripting (XSS) vulnerability in the Recent Comments module 5.x through 5.x-1.2 and 6.x through 6.x-1.0 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a "custom block title interface." | 2 | 3.5 | Low | 2017-01-18 | 2010-03-25 | View | |
| 12642 | CVE-2010-1108 | Cross-site scripting (XSS) vulnerability in the Control Panel module 5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote authenticated users, with "administer blocks" privileges, to inject arbitrary web script or HTML via unspecified vectors. | 2 | 3.5 | Low | 2017-01-18 | 2010-03-25 | View | |
| 12643 | CVE-2010-1109 | Multiple SQL injection vulnerabilities in index.php in phpMySport 1.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) v2 parameter in a member view action, (2) v1 parameter in a news action, (3) v1 parameter in an information action, (4) v2 parameter in a team view action, (5) v2 parameter in a club view action, or (6) v2 parameter in a matches view action. | 2 | 6.8 | Medium | 2017-01-18 | 2010-03-25 | View | |
| 12644 | CVE-2010-1110 | Directory traversal vulnerability in index.php in phpMySport 1.4 allows remote attackers to list arbitrary directories via a .. (dot dot) in the current_folder parameter. | 2 | 5 | Medium | 2017-01-18 | 2010-03-26 | View | |
| 12645 | CVE-2010-1111 | Multiple cross-site scripting (XSS) vulnerabilities in Jokes Complete Website allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to joke.php and the (2) searchingred parameter to results.php. | 2 | 4.3 | Medium | 2017-01-18 | 2010-03-26 | View |
Page 2529 of 17672, showing 5 records out of 88360 total, starting on record 12641, ending on 12645