Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 390 627

Количество 390 627

nvd логотип

CVE-2010-4856

почти 15 лет назад

SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4855

почти 15 лет назад

SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4854

почти 15 лет назад

SQL injection vulnerability in ajax/coupon.php in Zuitu 1.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a consume action.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2010-4853

почти 15 лет назад

SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewInv action to index.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4852

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in login.php in Eclime 1.1.2b allows remote attackers to inject arbitrary web script or HTML via the reason parameter in a fail action.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4851

почти 15 лет назад

Multiple SQL injection vulnerabilities in Eclime 1.1.2b allow remote attackers to execute arbitrary SQL commands via the (1) ref or (2) poll_id parameter to index.php, or the (3) country parameter to create_account.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4850

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Diferior 8.03 allow remote attackers to inject arbitrary web script or HTML via the (1) post_content parameter to post/edit/2/p1.html, related to views/post.php; the (2) slogan parameter to admin/site/2.html, related to views/admin.php; or the (3) subcatname or (4) description parameter to admin/forum/create_sub.html, related to views/admin.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4849

почти 15 лет назад

SQL injection vulnerability in countrydetails.php in Alibaba Clone B2B 3.4 allows remote attackers to execute arbitrary SQL commands via the es_id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4848

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in addlink.php in AXScripts AxsLinks 0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) title parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4847

почти 15 лет назад

SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4846

почти 15 лет назад

SQL injection vulnerability in view_item.php in MH Products Pay Pal Shop Digital allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4845

почти 15 лет назад

Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4844

почти 15 лет назад

SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary SQL commands via the kat parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4843

почти 15 лет назад

SQL injection vulnerability in website-page.php in PHP Web Scripts Ad Manager Pro 3.0 allows remote attackers to execute arbitrary SQL commands via the pageId parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4842

почти 15 лет назад

SQL injection vulnerability in admin/login.php in MHP DownloadScript (aka MH Products Download Center) 2.2 allows remote attackers to execute arbitrary SQL commands via the Name parameter. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4841

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine EventLog Analyzer 6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HOST_ID, (2) OS, (3) GROUP, (4) exportFile, (5) load, (6) type, or (7) tab parameter to INDEX.do, the (8) reported parameter to INDEX2.do, the (9) gId parameter to hostlist.do, the (10) newWindow parameter to globalSettings.do, or the (11) STATUS parameter to enableHost.do. Fixed in Build 9000.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4840

почти 15 лет назад

Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (SysEvttCol.exe process crash) or possibly execute arbitrary code via a long Syslog PRI message header to UDP port (1) 513 or (2) 514. Fixed in 7.2 Build 7020.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4839

почти 15 лет назад

SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-4838

почти 15 лет назад

SQL injection vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote authenticated users, with Public Back-end permissions, to execute arbitrary SQL commands via the alpha parameter in a (1) listTickets or (2) listFaqs action to administrator/index.php.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2010-4837

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the subject parameter (title field) in a saveTicket action to index2.php. NOTE: some of these details are obtained from third party information.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2010-4856

SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4855

SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4854

SQL injection vulnerability in ajax/coupon.php in Zuitu 1.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a consume action.

CVSS2: 6.8
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4853

SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewInv action to index.php.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4852

Cross-site scripting (XSS) vulnerability in login.php in Eclime 1.1.2b allows remote attackers to inject arbitrary web script or HTML via the reason parameter in a fail action.

CVSS2: 4.3
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4851

Multiple SQL injection vulnerabilities in Eclime 1.1.2b allow remote attackers to execute arbitrary SQL commands via the (1) ref or (2) poll_id parameter to index.php, or the (3) country parameter to create_account.php.

CVSS2: 7.5
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4850

Multiple cross-site scripting (XSS) vulnerabilities in Diferior 8.03 allow remote attackers to inject arbitrary web script or HTML via the (1) post_content parameter to post/edit/2/p1.html, related to views/post.php; the (2) slogan parameter to admin/site/2.html, related to views/admin.php; or the (3) subcatname or (4) description parameter to admin/forum/create_sub.html, related to views/admin.php.

CVSS2: 4.3
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4849

SQL injection vulnerability in countrydetails.php in Alibaba Clone B2B 3.4 allows remote attackers to execute arbitrary SQL commands via the es_id parameter.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4848

Multiple cross-site scripting (XSS) vulnerabilities in addlink.php in AXScripts AxsLinks 0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) title parameter.

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4847

SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4846

SQL injection vulnerability in view_item.php in MH Products Pay Pal Shop Digital allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4845

Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4844

SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary SQL commands via the kat parameter.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4843

SQL injection vulnerability in website-page.php in PHP Web Scripts Ad Manager Pro 3.0 allows remote attackers to execute arbitrary SQL commands via the pageId parameter.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4842

SQL injection vulnerability in admin/login.php in MHP DownloadScript (aka MH Products Download Center) 2.2 allows remote attackers to execute arbitrary SQL commands via the Name parameter. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4841

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine EventLog Analyzer 6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HOST_ID, (2) OS, (3) GROUP, (4) exportFile, (5) load, (6) type, or (7) tab parameter to INDEX.do, the (8) reported parameter to INDEX2.do, the (9) gId parameter to hostlist.do, the (10) newWindow parameter to globalSettings.do, or the (11) STATUS parameter to enableHost.do. Fixed in Build 9000.

CVSS2: 4.3
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4840

Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (SysEvttCol.exe process crash) or possibly execute arbitrary code via a long Syslog PRI message header to UDP port (1) 513 or (2) 514. Fixed in 7.2 Build 7020.

CVSS2: 7.5
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4839

SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action.

CVSS2: 7.5
3%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4838

SQL injection vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote authenticated users, with Public Back-end permissions, to execute arbitrary SQL commands via the alpha parameter in a (1) listTickets or (2) listFaqs action to administrator/index.php.

CVSS2: 6
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4837

Cross-site scripting (XSS) vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the subject parameter (title field) in a saveTicket action to index2.php. NOTE: some of these details are obtained from third party information.

CVSS2: 4.3
2%
Низкий
почти 15 лет назад

Уязвимостей на страницу