Show filters
735 Total Results
Displaying 611-620 of 735
Sort by:
Attacker Value
Unknown

CVE-2010-4724

Disclosure Date: February 03, 2011 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2010-4727

Disclosure Date: February 03, 2011 (last updated October 04, 2023)
Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2009-5053

Disclosure Date: February 03, 2011 (last updated October 04, 2023)
Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a cache file.
0
Attacker Value
Unknown

CVE-2010-3882

Disclosure Date: October 08, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.7.1 and earlier allow remote attackers to inject arbitrary web script or HTML via input to the (1) Add Pages, (2) Add Global Content, (3) Edit Global Content, (4) Add Article, (5) Add Category, (6) Add Field Definition, or (7) Add Shortcut module.
0
Attacker Value
Unknown

CVE-2010-3884

Disclosure Date: October 08, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that reset the administrative password. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2010-2797

Disclosure Date: October 08, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in lib/translation.functions.php in CMS Made Simple before 1.8.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the default_cms_lang parameter to an admin script, as demonstrated by admin/addbookmark.php, a different vulnerability than CVE-2008-5642.
0
Attacker Value
Unknown

CVE-2010-3883

Disclosure Date: October 08, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Change Group Permissions module in CMS Made Simple 1.7.1 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make permission modifications.
0
Attacker Value
Unknown

CVE-2010-3486

Disclosure Date: September 22, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash), (2) %5C (encoded backslash), or (3) %255c (double-encoded backslash) in the name parameter.
0
Attacker Value
Unknown

CVE-2010-3425

Disclosure Date: September 16, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly other 5.3 versions, allows remote attackers to inject arbitrary web script or HTML via the url parameter.
0
Attacker Value
Unknown

CVE-2009-4994

Disclosure Date: August 25, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
0