Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 393 962

Количество 393 962

nvd логотип

CVE-2011-5025

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web script or HTML via (1) the tag parameter to editTag.yaws, (2) the index parameter to showOldPage.yaws, (3) the node parameter to allRefsToMe.yaws, or (4) the text parameter to editPage.yaws.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-5024

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in mmsearch/design in the Mailman/htdig integration patch for Mailman allows remote attackers to inject arbitrary web script or HTML via the config parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-5023

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the search program, a different vulnerability than CVE-2011-3986.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-5022

больше 14 лет назад

SQL injection vulnerability in search.php in Pligg CMS 1.1.2 allows remote attackers to execute arbitrary SQL commands via the status parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-5021

больше 14 лет назад

PHPIDS before 0.7 does not properly implement Regular Expression Denial of Service (ReDoS) filters, which allows remote attackers to bypass rulesets and add PHP sequences to a file via unspecified vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-5020

больше 6 лет назад

An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2011-5019

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in setup/index.php in Textpattern CMS 4.4.1, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the ddb parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-5018

больше 6 лет назад

Koala Framework before 2011-11-21 has XSS via the request_uri parameter.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2011-5012

больше 14 лет назад

Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Reflection 2011 R1 before 15.3.2.569 and R1 SP1 before, Reflection 2011 R2 before 15.4.1.327, Reflection Windows Client 7.2 SP1 before hotfix 7.2.1186, and Reflection 14.1 SP1 before 14.1.1.206, allows remote FTP servers to execute arbitrary code via a long directory name in a response to a LIST command.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-5011

больше 14 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in xt:Commerce 3.0.4 SP2.1 and possibly earlier allow remote attackers to hijack the authentication of Admins for requests that (1) set a New user to Admin via the cID parameter to a statusconfirm action in admin/customers.php and (2) grant permissions to users via the cID parameter to a save action in admin/accounting.php.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-5010

больше 14 лет назад

apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters in the PINGADDRESS parameter for a "u" action.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2011-5009

больше 14 лет назад

The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a crafted Content-Length in an HTTP POST or (2) an invalid HTTP request method.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2011-5008

больше 14 лет назад

Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size value in the packet header, which triggers a heap-based buffer overflow.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-5007

больше 14 лет назад

Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.

CVSS2: 10
EPSS: Высокий
nvd логотип

CVE-2011-5006

больше 14 лет назад

Stack-based buffer overflow in QQPlayer 3.2.845 allows remote attackers to execute arbitrary code via a crafted PnSize value in a MOV file.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2011-5005

больше 14 лет назад

Unrestricted file upload vulnerability in QuiXplorer 2.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension using the upload action to index.php, then accessing it via a direct request to the file in an unspecified directory.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-5004

больше 14 лет назад

Unrestricted file upload vulnerability in models/importcsv.php in the Fabrik (com_fabrik) component before 2.1.1 for Joomla! allows remote authenticated users with Manager privileges to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2011-5003

больше 14 лет назад

Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier allows remote attackers to execute arbitrary code via a long request to TCP port 4659.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2011-5002

больше 14 лет назад

Multiple stack-based buffer overflows in Final Draft 8 before 8.02 allow remote attackers to execute arbitrary code via a .fdx or .fdxt file with long (1) Word, (2) Transition, (3) Location, (4) Extension, (5) SceneIntro, (6) TimeOfDay, and (7) Character elements.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-5001

больше 14 лет назад

Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613 allows remote attackers to execute arbitrary code via a crafted IPC packet to TCP port 20101.

CVSS2: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-5025

Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web script or HTML via (1) the tag parameter to editTag.yaws, (2) the index parameter to showOldPage.yaws, (3) the node parameter to allRefsToMe.yaws, or (4) the text parameter to editPage.yaws.

CVSS2: 4.3
3%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-5024

Cross-site scripting (XSS) vulnerability in mmsearch/design in the Mailman/htdig integration patch for Mailman allows remote attackers to inject arbitrary web script or HTML via the config parameter.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-5023

Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the search program, a different vulnerability than CVE-2011-3986.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-5022

SQL injection vulnerability in search.php in Pligg CMS 1.1.2 allows remote attackers to execute arbitrary SQL commands via the status parameter.

CVSS2: 7.5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-5021

PHPIDS before 0.7 does not properly implement Regular Expression Denial of Service (ReDoS) filters, which allows remote attackers to bypass rulesets and add PHP sequences to a file via unspecified vectors.

CVSS2: 7.5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-5020

An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2011-5019

Cross-site scripting (XSS) vulnerability in setup/index.php in Textpattern CMS 4.4.1, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the ddb parameter.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-5018

Koala Framework before 2011-11-21 has XSS via the request_uri parameter.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2011-5012

Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Reflection 2011 R1 before 15.3.2.569 and R1 SP1 before, Reflection 2011 R2 before 15.4.1.327, Reflection Windows Client 7.2 SP1 before hotfix 7.2.1186, and Reflection 14.1 SP1 before 14.1.1.206, allows remote FTP servers to execute arbitrary code via a long directory name in a response to a LIST command.

CVSS2: 10
8%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-5011

Multiple cross-site request forgery (CSRF) vulnerabilities in xt:Commerce 3.0.4 SP2.1 and possibly earlier allow remote attackers to hijack the authentication of Admins for requests that (1) set a New user to Admin via the cID parameter to a statusconfirm action in admin/customers.php and (2) grant permissions to users via the cID parameter to a save action in admin/accounting.php.

CVSS2: 6.8
3%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-5010

apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters in the PINGADDRESS parameter for a "u" action.

CVSS2: 10
65%
Средний
больше 14 лет назад
nvd логотип
CVE-2011-5009

The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a crafted Content-Length in an HTTP POST or (2) an invalid HTTP request method.

CVSS2: 5
10%
Средний
больше 14 лет назад
nvd логотип
CVE-2011-5008

Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size value in the packet header, which triggers a heap-based buffer overflow.

CVSS2: 7.5
5%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-5007

Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.

CVSS2: 10
73%
Высокий
больше 14 лет назад
nvd логотип
CVE-2011-5006

Stack-based buffer overflow in QQPlayer 3.2.845 allows remote attackers to execute arbitrary code via a crafted PnSize value in a MOV file.

CVSS2: 9.3
6%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-5005

Unrestricted file upload vulnerability in QuiXplorer 2.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension using the upload action to index.php, then accessing it via a direct request to the file in an unspecified directory.

CVSS2: 7.5
4%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-5004

Unrestricted file upload vulnerability in models/importcsv.php in the Fabrik (com_fabrik) component before 2.1.1 for Joomla! allows remote authenticated users with Manager privileges to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

CVSS2: 6
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-5003

Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier allows remote attackers to execute arbitrary code via a long request to TCP port 4659.

CVSS2: 10
62%
Средний
больше 14 лет назад
nvd логотип
CVE-2011-5002

Multiple stack-based buffer overflows in Final Draft 8 before 8.02 allow remote attackers to execute arbitrary code via a .fdx or .fdxt file with long (1) Word, (2) Transition, (3) Location, (4) Extension, (5) SceneIntro, (6) TimeOfDay, and (7) Character elements.

CVSS2: 10
8%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-5001

Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613 allows remote attackers to execute arbitrary code via a crafted IPC packet to TCP port 20101.

CVSS2: 10
64%
Средний
больше 14 лет назад

Уязвимостей на страницу