Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-4872 | 1 Pilotcart | 1 Pilot Cart | 2017-08-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in newsroom.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL commands via the specific parameter. | |||||
CVE-2010-4873 | 1 Webidsupport | 1 Webid | 2017-08-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |||||
CVE-2010-4875 | 2 Wordpress, Xondie | 2 Wordpress, Vodpod Video Gallery | 2017-08-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery Plugin 3.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gid parameter. | |||||
CVE-2010-4883 | 1 Modx | 1 Revolution | 2017-08-28 | 2.6 LOW | N/A |
Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inject arbitrary web script or HTML via the modhash parameter. | |||||
CVE-2010-4893 | 1 Festengine | 1 Festos | 2017-08-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in foodvendors.php in FestOS 2.3b allows remote attackers to inject arbitrary web script or HTML via the category parameter in a details action. | |||||
CVE-2010-4894 | 1 Chillycms | 1 Chillycms | 2017-08-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information. | |||||
CVE-2010-4895 | 1 Chillycms | 1 Chillycms | 2017-08-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the username field). NOTE: some of these details are obtained from third party information. | |||||
CVE-2010-4896 | 1 Expinion.net | 1 Member Management System | 2017-08-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in admin/index.asp in Member Management System 4.0 allows remote attackers to inject arbitrary web script or HTML via the REF_URL parameter. | |||||
CVE-2010-4908 | 1 Virtuenetz | 1 Virtue Shopping Mall | 2017-08-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in detail.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the prodid parameter. | |||||
CVE-2010-4910 | 1 Coldgen | 1 Coldcalendar | 2017-08-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.cfm in ColdGen ColdCalendar 2.06 allows remote attackers to execute arbitrary SQL commands via the EventID parameter in a ViewEventDetails action. | |||||
CVE-2010-4911 | 1 Sellatsite | 1 Php Classifieds Ads | 2017-08-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL commands via the sid parameter. | |||||
CVE-2010-4912 | 1 Discuz | 1 Ucenter Home | 2017-08-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid parameter in a view action. | |||||
CVE-2010-4914 | 1 Deltascripts | 1 Php Classifieds | 2017-08-28 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter. | |||||
CVE-2010-4915 | 1 Coldgen | 1 Coldbookmarks | 2017-08-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL commands via the BookmarkID parameter in an EditBookmark action. | |||||
CVE-2010-4916 | 1 Coldgen | 1 Coldusergroup | 2017-08-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in index.cfm in ColdGen ColdUserGroup 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) ArticleID or (2) LibraryID parameter. | |||||
CVE-2010-4917 | 1 A-blog | 1 A-blog | 2017-08-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in sources/search.php in A-Blog 2.0 allows remote attackers to execute arbitrary SQL commands via the words parameter. | |||||
CVE-2010-4918 | 2 Ijoomla, Joomla | 2 Com Magazine, Joomla\! | 2017-08-28 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in iJoomla Magazine (com_magazine) component 3.0.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the config parameter to magazine.functions.php. | |||||
CVE-2010-4919 | 1 Micronetsoft | 1 Rv Dealer Website | 2017-08-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in detail.asp in Micronetsoft RV Dealer Website 1.0 allows remote attackers to execute arbitrary SQL commands via the vehicletypeID parameter. | |||||
CVE-2010-4920 | 1 Micronetsoft | 1 Rental Property Website | 2017-08-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in detail.asp in Micronetsoft Rental Property Management Website 1.0 allows remote attackers to execute arbitrary SQL commands via the ad_ID parameter. | |||||
CVE-2010-4921 | 1 Dmxready | 1 Polling Booth Manager | 2017-08-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in inc_pollingboothmanager.asp in DMXReady Polling Booth Manager allows remote attackers to execute arbitrary SQL commands via the QuestionID parameter in a results action. |