Show filters
530 Total Results
Displaying 371-380 of 530
Sort by:
Attacker Value
Unknown
CVE-2010-2671
Disclosure Date: July 08, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to inject arbitrary web script or HTML via the subTreeItem parameter.
0
Attacker Value
Unknown
CVE-2010-1168
Disclosure Date: June 21, 2010 (last updated October 04, 2023)
The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
0
Attacker Value
Unknown
CVE-2010-2341
Disclosure Date: June 18, 2010 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the tpl_base_dir parameter.
0
Attacker Value
Unknown
CVE-2009-4827
Disclosure Date: April 27, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a change action.
0
Attacker Value
Unknown
CVE-2009-4826
Disclosure Date: April 27, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authentication of administrators for requests that alter administrative settings via a cp action.
0
Attacker Value
Unknown
CVE-2009-4682
Disclosure Date: March 10, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via the id parameter in a vote action.
0
Attacker Value
Unknown
CVE-2009-4683
Disclosure Date: March 10, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter in a dovote action. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2010-0958
Disclosure Date: March 10, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in modules/hayoo/index.php in Tribisur 2.1, 2.0, and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via directory traversal sequences in the theme parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2010-0370
Disclosure Date: January 21, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Node Blocks module 5.x-1.1 and earlier, and 6.x-1.3 and earlier, a module for Drupal, allows remote authenticated users, with permissions to create or edit content and administer blocks, to inject arbitrary web script or HTML via the edit-title parameter (aka block title).
0
Attacker Value
Unknown
CVE-2009-4450
Disclosure Date: December 29, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) lat, (2) lng, and (3) zom parameters, which are not properly handled when processed with templates/map.tpl.
0