NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 15876 | CVE-2010-4629 | MyBB (aka MyBulletinBoard) before 1.4.12 does not properly restrict uid values for group join requests, which allows remote attackers to cause a denial of service (resource consumption) by using guest access to submit join request forms for moderated groups, related to usercp.php and managegroup.php. | 2 | 5 | Medium | 2017-01-18 | 2011-01-11 | View | |
| 15877 | CVE-2010-4630 | Cross-site scripting (XSS) vulnerability in pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2010-12-31 | View | |
| 15878 | CVE-2010-4631 | Multiple cross-site scripting (XSS) vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) countrycode parameter to contact.asp, USERNAME parameter to (2) gateway.asp and (3) cart.asp, and the specific parameter to (4) quote.asp and (5) buyitnow. | 2 | 4.3 | Medium | 2017-01-18 | 2010-12-31 | View | |
| 15879 | CVE-2010-4632 | Multiple SQL injection vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to execute arbitrary SQL commands via the (1) article parameter to kb.asp, (2) specific parameter to cart.asp, (3) countrycode parameter to contact.asp, and the (4) srch parameter to search.asp. NOTE: the article parameter to pilot.asp is already covered by CVE-2008-2688. | 2 | 7.5 | High | 2017-01-18 | 2010-12-31 | View | |
| 15880 | CVE-2010-4633 | SQL injection vulnerability in cart.php in digiSHOP 2.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vulnerability than CVE-2005-4614.1. | 2 | 7.5 | High | 2017-01-18 | 2010-12-31 | View |
Page 3176 of 17672, showing 5 records out of 88360 total, starting on record 15876, ending on 15880