NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
13731  CVE-2010-2253  lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a . (dot) character, which allows remote servers to create or overwrite files via (1) a 3xx redirect to a URL with a crafted filename or (2) a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.    6.8  Medium  2017-01-18  2010-11-06  View
13732  CVE-2010-2254  SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php.    7.5  High  2017-01-18  2010-06-10  View
13733  CVE-2010-2255  SQL injection vulnerability in the BF Survey Pro (com_bfsurvey_pro) component before 1.3.1, BF Survey Pro Free (com_bfsurvey_profree) component 1.2.6, and BF Survey Basic component before 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-18  2010-06-10  View
13734  CVE-2010-2256  Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to videos.php.    4.3  Medium  2017-01-18  2010-06-10  View
13735  CVE-2010-2257  SQL injection vulnerability in index_ie.php in Pay Per Minute Video Chat Script 2.0 and 2.1 allows remote attackers to execute arbitrary SQL commands via the page parameter.    7.5  High  2017-01-18  2010-06-10  View

Page 2747 of 17672, showing 5 records out of 88360 total, starting on record 13731, ending on 13735

Actions