Show filters
320 Total Results
Displaying 231-240 of 320
Sort by:
Attacker Value
Unknown

CVE-2012-1048

Disclosure Date: February 12, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.
0
Attacker Value
Unknown

CVE-2011-4808

Disclosure Date: December 14, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a fnd_home action to index.php.
0
Attacker Value
Unknown

CVE-2011-4809

Disclosure Date: December 14, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) language[], (2) university[], (3) persent[], (4) company_name[], (5) designation[], (6) music[], (7) books[], (8) movies[], (9) games[], (10) syp[], (11) ft[], and (12) fa[] parameters in a save task for a profile to index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2011-3330

Disclosure Date: November 04, 2011 (last updated October 04, 2023)
Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers, to execute arbitrary code via an unspecified system parameter.
0
Attacker Value
Unknown

CVE-2010-5015

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in view_photo.php in 2daybiz Network Community Script allows remote attackers to execute arbitrary SQL commands via the alb parameter.
0
Attacker Value
Unknown

CVE-2011-1911

Disclosure Date: September 20, 2011 (last updated October 04, 2023)
JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach.
0
Attacker Value
Unknown

CVE-2010-2696

Disclosure Date: July 12, 2010 (last updated October 04, 2023)
SQL injection vulnerability in gallery/index.php in Sijio Community Software allows remote attackers to execute arbitrary SQL commands via the parent parameter.
0
Attacker Value
Unknown

CVE-2010-2698

Disclosure Date: July 12, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Sijio Community Software allow remote authenticated users to inject arbitrary web script or HTML via the title parameter when (1) editing a new blog, (2) adding an album, or (3) editing an album. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2010-2697

Disclosure Date: July 12, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitrary web script or HTML via the title parameter when adding a new blog, related to edit_blog/index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-2508

Disclosure Date: June 28, 2010 (last updated October 04, 2023)
SQL injection vulnerability in user-profile.php in 2daybiz Video Community Portal Script allows remote attackers to execute arbitrary SQL commands via the userid parameter.
0