NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
14841  CVE-2010-3460  Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL.    Medium  2017-01-18  2010-09-20  View
14842  CVE-2010-3461  SQL injection vulnerability in the Publisher module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printarticle action to mod.php, a different vector than CVE-2007-3394.    7.5  High  2017-01-18  2010-09-20  View
14843  CVE-2010-3462  Cross-site scripting (XSS) vulnerability in backend/plugin/Registration/index.php in Mollify 1.6, 1.6.5.5, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the confirm parameter. NOTE: some of these details are obtained from third party information.    4.3  Medium  2017-01-18  2010-09-20  View
14844  CVE-2010-3463  Cross-site scripting (XSS) vulnerability in modules/search/search.class.php in SantaFox 2.02, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the search parameter to search.html.    4.3  Medium  2017-01-18  2010-09-20  View
14845  CVE-2010-3464  Cross-site request forgery (CSRF) vulnerability in admin/manager_users.class.php in SantaFox 2.02, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests, as demonstrated by adding administrative users via the save_admin action to admin/index.php.    6.8  Medium  2017-01-18  2010-09-20  View

Page 2969 of 17672, showing 5 records out of 88360 total, starting on record 14841, ending on 14845

Actions