Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 390 627

Количество 390 627

nvd логотип

CVE-2010-4916

почти 15 лет назад

Multiple SQL injection vulnerabilities in index.cfm in ColdGen ColdUserGroup 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) ArticleID or (2) LibraryID parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4915

почти 15 лет назад

SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL commands via the BookmarkID parameter in an EditBookmark action.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4914

почти 15 лет назад

PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4913

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in the search feature in ColdGen ColdUserGroup 1.06 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some of these details are obtained from third party information.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4912

почти 15 лет назад

SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid parameter in a view action.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4911

почти 15 лет назад

SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL commands via the sid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4910

почти 15 лет назад

SQL injection vulnerability in index.cfm in ColdGen ColdCalendar 2.06 allows remote attackers to execute arbitrary SQL commands via the EventID parameter in a ViewEventDetails action.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4909

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PaysiteReviewCMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to search.php or the (2) image parameter to image.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4908

почти 15 лет назад

SQL injection vulnerability in detail.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the prodid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4907

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter. NOTE: the from parameter is already covered by CVE-2009-4562.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4906

почти 15 лет назад

SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a parameter. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4905

почти 15 лет назад

SQL injection vulnerability in article_details.php in Softbiz Article Directory Script allows remote attackers to execute arbitrary SQL commands via the sbiz_id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4904

почти 15 лет назад

SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_name parameter in a view action to index.php. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4903

почти 15 лет назад

SQL injection vulnerability in index.php in CubeCart 4.3.3 allows remote attackers to execute arbitrary SQL commands via the searchStr parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4902

почти 15 лет назад

Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgame parameter to index.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4901

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4900

почти 15 лет назад

Open redirect vulnerability in c.php in CMS WebManager-Pro 8.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2010-4899

почти 15 лет назад

SQL injection vulnerability in c.php in CMS WebManager-Pro before 8.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4898

почти 15 лет назад

SQL injection vulnerability in the Gantry (com_gantry) component 3.0.10 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter to index.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4897

почти 15 лет назад

SQL injection vulnerability in comment.php in BlueCMS 1.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header in a send action.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2010-4916

Multiple SQL injection vulnerabilities in index.cfm in ColdGen ColdUserGroup 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) ArticleID or (2) LibraryID parameter.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4915

SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL commands via the BookmarkID parameter in an EditBookmark action.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4914

PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter.

CVSS2: 7.5
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4913

Cross-site scripting (XSS) vulnerability in the search feature in ColdGen ColdUserGroup 1.06 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some of these details are obtained from third party information.

CVSS2: 4.3
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4912

SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid parameter in a view action.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4911

SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL commands via the sid parameter.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4910

SQL injection vulnerability in index.cfm in ColdGen ColdCalendar 2.06 allows remote attackers to execute arbitrary SQL commands via the EventID parameter in a ViewEventDetails action.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4909

Multiple cross-site scripting (XSS) vulnerabilities in PaysiteReviewCMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to search.php or the (2) image parameter to image.php.

CVSS2: 4.3
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4908

SQL injection vulnerability in detail.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the prodid parameter.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4907

Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter. NOTE: the from parameter is already covered by CVE-2009-4562.

CVSS2: 4.3
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4906

SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a parameter. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4905

SQL injection vulnerability in article_details.php in Softbiz Article Directory Script allows remote attackers to execute arbitrary SQL commands via the sbiz_id parameter.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4904

SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_name parameter in a view action to index.php. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4903

SQL injection vulnerability in index.php in CubeCart 4.3.3 allows remote attackers to execute arbitrary SQL commands via the searchStr parameter.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4902

Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgame parameter to index.php.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4901

Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter.

CVSS2: 4.3
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4900

Open redirect vulnerability in c.php in CMS WebManager-Pro 8.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

CVSS2: 5.8
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4899

SQL injection vulnerability in c.php in CMS WebManager-Pro before 8.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4898

SQL injection vulnerability in the Gantry (com_gantry) component 3.0.10 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter to index.php.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4897

SQL injection vulnerability in comment.php in BlueCMS 1.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header in a send action.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад

Уязвимостей на страницу