Show filters
735 Total Results
Displaying 611-620 of 735
Sort by:
Attacker Value
Unknown
CVE-2010-4724
Disclosure Date: February 03, 2011 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.
0
Attacker Value
Unknown
CVE-2010-4727
Disclosure Date: February 03, 2011 (last updated October 04, 2023)
Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.
0
Attacker Value
Unknown
CVE-2009-5053
Disclosure Date: February 03, 2011 (last updated October 04, 2023)
Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a cache file.
0
Attacker Value
Unknown
CVE-2010-3882
Disclosure Date: October 08, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.7.1 and earlier allow remote attackers to inject arbitrary web script or HTML via input to the (1) Add Pages, (2) Add Global Content, (3) Edit Global Content, (4) Add Article, (5) Add Category, (6) Add Field Definition, or (7) Add Shortcut module.
0
Attacker Value
Unknown
CVE-2010-3884
Disclosure Date: October 08, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that reset the administrative password. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2010-2797
Disclosure Date: October 08, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in lib/translation.functions.php in CMS Made Simple before 1.8.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the default_cms_lang parameter to an admin script, as demonstrated by admin/addbookmark.php, a different vulnerability than CVE-2008-5642.
0
Attacker Value
Unknown
CVE-2010-3883
Disclosure Date: October 08, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Change Group Permissions module in CMS Made Simple 1.7.1 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make permission modifications.
0
Attacker Value
Unknown
CVE-2010-3486
Disclosure Date: September 22, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash), (2) %5C (encoded backslash), or (3) %255c (double-encoded backslash) in the name parameter.
0
Attacker Value
Unknown
CVE-2010-3425
Disclosure Date: September 16, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly other 5.3 versions, allows remote attackers to inject arbitrary web script or HTML via the url parameter.
0
Attacker Value
Unknown
CVE-2009-4994
Disclosure Date: August 25, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
0