NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
15586  CVE-2010-4331  Multiple cross-site scripting (XSS) vulnerabilities in Seo Panel 2.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) default_news or (2) sponsors cookies, which are not properly handled by (a) controllers/index.ctrl.php or (b) controllers/settings.ctrl.php.    4.3  Medium  2017-01-18  2011-01-24  View
15587  CVE-2010-4332  Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies.    7.5  High  2017-01-18  2011-01-11  View
15588  CVE-2010-4333  Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies.    7.5  High  2017-01-18  2013-08-30  View
15589  CVE-2010-4334  The IO::Socket::SSL module 1.35 for Perl, when verify_mode is not VERIFY_NONE, fails open to VERIFY_NONE instead of throwing an error when a ca_file/ca_path cannot be verified, which allows remote attackers to bypass intended certificate restrictions.    Medium  2017-01-18  2011-10-13  View
15590  CVE-2010-4335  The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.    7.5  High  2017-01-18  2011-01-22  View

Page 3118 of 17672, showing 5 records out of 88360 total, starting on record 15586, ending on 15590

Actions