Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 389 227

Количество 389 227

nvd логотип

CVE-2010-2472

почти 7 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2010-2471

почти 7 лет назад

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2010-2470

около 16 лет назад

Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files in these directories, a different vulnerability than CVE-2010-0180.

CVSS2: 1.9
EPSS: Низкий
nvd логотип

CVE-2010-2469

около 16 лет назад

The Linear eMerge 50 and 5000 uses a default password of eMerge for the IEIeMerge account, which makes it easier for remote attackers to obtain Video Recorder data by establishing a session to the device.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-2468

около 16 лет назад

The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Administrator password, which makes it easier for context-dependent attackers to obtain privileged access by recovering the cleartext of this password.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2010-2467

около 16 лет назад

The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, which makes it easier for remote attackers to download backup files via unspecified FTP requests.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-2466

около 16 лет назад

The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloading of database backups, which allows remote attackers to obtain sensitive information via requests for full_*.dar files with predictable filenames.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-2465

около 16 лет назад

The S2 Security NetBox 2.5, 3.3, and 4.0, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download node logs, photographs of persons, and backup files via unspecified HTTP requests.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-2464

около 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2463

около 16 лет назад

Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2462

около 16 лет назад

SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-2461

около 16 лет назад

SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-2460

около 16 лет назад

SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-2459

около 16 лет назад

SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-2458

около 16 лет назад

Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the videoid parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2457

около 16 лет назад

Cross-site scripting (XSS) vulnerability in index.php in K-Search allows remote attackers to inject arbitrary web script or HTML via the term parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2456

около 16 лет назад

Multiple directory traversal vulnerabilities in index.php in Linker IMG 1.0 and earlier allow remote attackers to read and execute arbitrary local files via a URL in the (1) cook_lan cookie parameter ($lan_dir variable) or possibly (2) Sdb_type parameter. NOTE: this was originally reported as remote file inclusion, but this may be inaccurate.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2010-2455

около 16 лет назад

Opera does not properly manage the address bar between the request to open a URL and the retrieval of the new document's content, which might allow remote attackers to conduct spoofing attacks via a crafted HTML document, a related issue to CVE-2010-1206.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2454

около 16 лет назад

Apple Safari does not properly manage the address bar between the request to open a URL and the retrieval of the new document's content, which might allow remote attackers to conduct spoofing attacks via a crafted HTML document, a related issue to CVE-2010-1206.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2453

почти 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Synology Disk Station 2.x before DSM3.0-1337 allow remote attackers to inject arbitrary web script or HTML by connecting to the FTP server and providing a crafted (1) USER or (2) PASS command, which is written by the FTP logging module to a web-interface log window, related to a "web commands injection" issue.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2010-2472

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2010-2471

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2010-2470

Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files in these directories, a different vulnerability than CVE-2010-0180.

CVSS2: 1.9
0%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2469

The Linear eMerge 50 and 5000 uses a default password of eMerge for the IEIeMerge account, which makes it easier for remote attackers to obtain Video Recorder data by establishing a session to the device.

CVSS2: 5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2468

The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Administrator password, which makes it easier for context-dependent attackers to obtain privileged access by recovering the cleartext of this password.

CVSS2: 10
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2467

The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, which makes it easier for remote attackers to download backup files via unspecified FTP requests.

CVSS2: 5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2466

The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloading of database backups, which allows remote attackers to obtain sensitive information via requests for full_*.dar files with predictable filenames.

CVSS2: 5
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2465

The S2 Security NetBox 2.5, 3.3, and 4.0, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download node logs, photographs of persons, and backup files via unspecified HTTP requests.

CVSS2: 5
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2464

Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.

CVSS2: 4.3
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2463

Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.

CVSS2: 4.3
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2462

SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action.

CVSS2: 7.5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2461

SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store parameter.

CVSS2: 7.5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2460

SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter.

CVSS2: 7.5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2459

SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter.

CVSS2: 7.5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2458

Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the videoid parameter.

CVSS2: 4.3
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2457

Cross-site scripting (XSS) vulnerability in index.php in K-Search allows remote attackers to inject arbitrary web script or HTML via the term parameter.

CVSS2: 4.3
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2456

Multiple directory traversal vulnerabilities in index.php in Linker IMG 1.0 and earlier allow remote attackers to read and execute arbitrary local files via a URL in the (1) cook_lan cookie parameter ($lan_dir variable) or possibly (2) Sdb_type parameter. NOTE: this was originally reported as remote file inclusion, but this may be inaccurate.

CVSS2: 6.8
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2455

Opera does not properly manage the address bar between the request to open a URL and the retrieval of the new document's content, which might allow remote attackers to conduct spoofing attacks via a crafted HTML document, a related issue to CVE-2010-1206.

CVSS2: 4.3
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2454

Apple Safari does not properly manage the address bar between the request to open a URL and the retrieval of the new document's content, which might allow remote attackers to conduct spoofing attacks via a crafted HTML document, a related issue to CVE-2010-1206.

CVSS2: 4.3
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2453

Multiple cross-site scripting (XSS) vulnerabilities in Synology Disk Station 2.x before DSM3.0-1337 allow remote attackers to inject arbitrary web script or HTML by connecting to the FTP server and providing a crafted (1) USER or (2) PASS command, which is written by the FTP logging module to a web-interface log window, related to a "web commands injection" issue.

CVSS2: 4.3
1%
Низкий
почти 16 лет назад

Уязвимостей на страницу