NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
12666  CVE-2010-1132  The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.    9.3  High  2017-01-18  2011-02-01  View
12667  CVE-2010-1133  Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) tiki-searchindex.php and (2) tiki-searchresults.php.    7.5  High  2017-01-18  2012-10-24  View
12668  CVE-2010-1134  SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable.    7.5  High  2017-01-18  2012-10-24  View
12669  CVE-2010-1135  The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.    7.5  High  2017-01-18  2012-10-24  View
12670  CVE-2010-1136  The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php.    7.5  High  2017-01-18  2012-10-24  View

Page 2534 of 17672, showing 5 records out of 88360 total, starting on record 12666, ending on 12670

Actions