NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
12640  CVE-2010-1106  PHP remote file inclusion vulnerability in cgi/index.php in AdvertisementManager 3.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the req parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.    7.5  High  2017-01-18  2010-03-25  View
12896  CVE-2010-1364  SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-18  2010-04-14  View
13408  CVE-2010-1916  The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote attackers to bypass intended access restrictions and modify the configuration of arbitrary plugins via (1) crafted backend_config_secret_key_location and backend_config_hash parameters that are used in a SHA1 hash of a shared secret that can be known or externally influenced, which are not properly handled by the "Deprecated config passing" feature; or (2) crafted backend_data and backend_data[key_location] variables, which are not properly handled by the xinha_read_passed_data function. NOTE: this can be leveraged to upload and possibly execute arbitrary files via config.inc.php in the ImageManager plugin.    7.5  High  2017-01-18  2010-06-13  View
78944  CVE-2001-1513  Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing "/" (slash), as demonstrated using ctx.    7.5  High  2017-01-05  2008-09-10  View
79200  CVE-2002-0188  Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the second variant of the "Content Disposition" vulnerability.    7.5  High  2017-01-05  2008-09-05  View

Page 3031 of 17672, showing 5 records out of 88360 total, starting on record 15151, ending on 15155

Actions