Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 390 627

Количество 390 627

nvd логотип

CVE-2010-5096

около 14 лет назад

Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the keywords parameter in a (1) do_search action to search.php or (2) do_stuff action to private.php. NOTE: the vendor disputes this issue, saying "Although this doesn't lead to an SQL injection, it does provide a general MyBB SQL error.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-5095

около 14 лет назад

Cross-site scripting (XSS) vulnerability in SilverStripe 2.3.x before 2.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to DataObjectSet pagination.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-5094

около 14 лет назад

The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x before 2.3.7 does not require ADMIN permissions, which allows remote attackers to delete index.php and "disrupt mod_rewrite-less URL routing."

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-5093

около 14 лет назад

Member_ProfileForm in security/Member.php in SilverStripe 2.3.x before 2.3.7 allows remote attackers to hijack user accounts by saving data using the email address (ID) of another user.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-5092

около 14 лет назад

The Add Member dialog in the Security admin page in SilverStripe 2.4.0 saves user passwords in plaintext, which allows local users to obtain sensitive information by reading a database.

CVSS2: 1.9
EPSS: Низкий
nvd логотип

CVE-2010-5091

около 14 лет назад

The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS author privileges to execute arbitrary PHP code by changing the extension of an uploaded file.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2010-5090

около 14 лет назад

SilverStripe before 2.4.2 allows remote authenticated users to change administrator passwords via vectors related to admin/security.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2010-5089

около 14 лет назад

SilverStripe before 2.4.2 does not properly restrict access to pages in draft mode, which allows remote attackers to obtain sensitive information.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-5088

около 14 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in SilverStripe 2.3.x before 2.3.9 and 2.4.x before 2.4.3 allow remote attackers to hijack the authentication of administrators via destructive controller actions, a different vulnerability than CVE-2010-5087.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2010-5087

около 14 лет назад

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication of administrators via vectors related to "form action requests" using a controller.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-5086

больше 14 лет назад

Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the style parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-5085

больше 14 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in admin/update_user in Hulihan Amethyst 0.1.5, and possibly earlier, allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrative password or (2) change the site's configuration.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2010-5084

больше 14 лет назад

The cross-site request forgery (CSRF) protection mechanism in e107 before 0.7.23 uses a predictable random token based on the creation date of the administrator account, which allows remote attackers to hijack the authentication of administrators for requests that add new users via e107_admin/users.php.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2010-5083

больше 14 лет назад

SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-5082

больше 14 лет назад

Untrusted search path vulnerability in colorcpl.exe 6.0.6000.16386 in the Color Control Panel in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges via a Trojan horse sti.dll file in the current working directory, as demonstrated by a directory that contains a .camp, .cdmp, .gmmp, .icc, or .icm file, aka "Color Control Panel Insecure Library Loading Vulnerability."

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2010-5081

больше 14 лет назад

Stack-based buffer overflow in Mini-Stream RM-MP3 Converter 3.1.2.1 allows remote attackers to execute arbitrary code via a long URL in a .pls file.

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2010-5080

около 14 лет назад

The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a password through email, which allows remote attackers to obtain sensitive data and hijack the session via the HTTP referer logs on a server, aka "HTTP referer leakage."

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2010-5079

почти 14 лет назад

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) "forgot password" functionality, and (4) password salts, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-5078

почти 14 лет назад

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain version information via a direct request to (1) apphire/silverstripe_version or (2) cms/silverstripe_version.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-5077

почти 12 лет назад

server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.

CVSS2: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2010-5096

Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the keywords parameter in a (1) do_search action to search.php or (2) do_stuff action to private.php. NOTE: the vendor disputes this issue, saying "Although this doesn't lead to an SQL injection, it does provide a general MyBB SQL error.

CVSS2: 7.5
6%
Низкий
около 14 лет назад
nvd логотип
CVE-2010-5095

Cross-site scripting (XSS) vulnerability in SilverStripe 2.3.x before 2.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to DataObjectSet pagination.

CVSS2: 4.3
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2010-5094

The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x before 2.3.7 does not require ADMIN permissions, which allows remote attackers to delete index.php and "disrupt mod_rewrite-less URL routing."

CVSS2: 5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2010-5093

Member_ProfileForm in security/Member.php in SilverStripe 2.3.x before 2.3.7 allows remote attackers to hijack user accounts by saving data using the email address (ID) of another user.

CVSS2: 5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2010-5092

The Add Member dialog in the Security admin page in SilverStripe 2.4.0 saves user passwords in plaintext, which allows local users to obtain sensitive information by reading a database.

CVSS2: 1.9
0%
Низкий
около 14 лет назад
nvd логотип
CVE-2010-5091

The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS author privileges to execute arbitrary PHP code by changing the extension of an uploaded file.

CVSS2: 6
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2010-5090

SilverStripe before 2.4.2 allows remote authenticated users to change administrator passwords via vectors related to admin/security.

CVSS2: 4
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2010-5089

SilverStripe before 2.4.2 does not properly restrict access to pages in draft mode, which allows remote attackers to obtain sensitive information.

CVSS2: 4.3
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2010-5088

Multiple cross-site request forgery (CSRF) vulnerabilities in SilverStripe 2.3.x before 2.3.9 and 2.4.x before 2.4.3 allow remote attackers to hijack the authentication of administrators via destructive controller actions, a different vulnerability than CVE-2010-5087.

CVSS2: 6.8
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2010-5087

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication of administrators via vectors related to "form action requests" using a controller.

CVSS2: 5
3%
Низкий
около 14 лет назад
nvd логотип
CVE-2010-5086

Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the style parameter.

CVSS2: 5
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-5085

Multiple cross-site request forgery (CSRF) vulnerabilities in admin/update_user in Hulihan Amethyst 0.1.5, and possibly earlier, allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrative password or (2) change the site's configuration.

CVSS2: 6.8
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-5084

The cross-site request forgery (CSRF) protection mechanism in e107 before 0.7.23 uses a predictable random token based on the creation date of the administrator account, which allows remote attackers to hijack the authentication of administrators for requests that add new users via e107_admin/users.php.

CVSS2: 6
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-5083

SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php.

CVSS2: 7.5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-5082

Untrusted search path vulnerability in colorcpl.exe 6.0.6000.16386 in the Color Control Panel in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges via a Trojan horse sti.dll file in the current working directory, as demonstrated by a directory that contains a .camp, .cdmp, .gmmp, .icc, or .icm file, aka "Color Control Panel Insecure Library Loading Vulnerability."

CVSS2: 9.3
15%
Средний
больше 14 лет назад
nvd логотип
CVE-2010-5081

Stack-based buffer overflow in Mini-Stream RM-MP3 Converter 3.1.2.1 allows remote attackers to execute arbitrary code via a long URL in a .pls file.

CVSS2: 9.3
31%
Средний
больше 14 лет назад
nvd логотип
CVE-2010-5080

The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a password through email, which allows remote attackers to obtain sensitive data and hijack the session via the HTTP referer logs on a server, aka "HTTP referer leakage."

CVSS2: 6.8
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2010-5079

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) "forgot password" functionality, and (4) password salts, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors.

CVSS2: 5
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2010-5078

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain version information via a direct request to (1) apphire/silverstripe_version or (2) cms/silverstripe_version.

CVSS2: 5
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2010-5077

server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.

CVSS2: 7.8
2%
Низкий
почти 12 лет назад

Уязвимостей на страницу