Show filters
530 Total Results
Displaying 371-380 of 530
Sort by:
Attacker Value
Unknown

CVE-2010-2671

Disclosure Date: July 08, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to inject arbitrary web script or HTML via the subTreeItem parameter.
0
Attacker Value
Unknown

CVE-2010-1168

Disclosure Date: June 21, 2010 (last updated October 04, 2023)
The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
0
Attacker Value
Unknown

CVE-2010-2341

Disclosure Date: June 18, 2010 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the tpl_base_dir parameter.
0
Attacker Value
Unknown

CVE-2009-4827

Disclosure Date: April 27, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a change action.
0
Attacker Value
Unknown

CVE-2009-4826

Disclosure Date: April 27, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authentication of administrators for requests that alter administrative settings via a cp action.
0
Attacker Value
Unknown

CVE-2009-4682

Disclosure Date: March 10, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via the id parameter in a vote action.
0
Attacker Value
Unknown

CVE-2009-4683

Disclosure Date: March 10, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter in a dovote action. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-0958

Disclosure Date: March 10, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in modules/hayoo/index.php in Tribisur 2.1, 2.0, and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via directory traversal sequences in the theme parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-0370

Disclosure Date: January 21, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Node Blocks module 5.x-1.1 and earlier, and 6.x-1.3 and earlier, a module for Drupal, allows remote authenticated users, with permissions to create or edit content and administer blocks, to inject arbitrary web script or HTML via the edit-title parameter (aka block title).
0
Attacker Value
Unknown

CVE-2009-4450

Disclosure Date: December 29, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) lat, (2) lng, and (3) zom parameters, which are not properly handled when processed with templates/map.tpl.
0