CVE-2011-4000 to CVE-2011-4999
200 CVEs with public proof-of-concept exploits.
- CVE-2011-40242 PoCsCross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary…
- CVE-2011-40262 PoCsSQL injection vulnerability in thanks.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2011-40291 PoCThe LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to…
- CVE-2011-40341 PoCBuffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian…
- CVE-2011-40403 PoCsBuffer overflow in MiniSmtp 3.0.11818 in NJStar Communicator allows remote attackers to execute arbitrary code via a crafted packet.
- CVE-2011-40411 PoCwebvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long…
- CVE-2011-40421 PoCAn unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers…
- CVE-2011-40431 PoCInteger overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue…
- CVE-2011-40443 PoCsAn unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers…
- CVE-2011-40451 PoCBuffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows…
- CVE-2011-40501 PoCBuffer overflow in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) 9.0.0.11200 allows remote attackers to cause a denial of…
- CVE-2011-40512 PoCsCEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication,…
- CVE-2011-40622 PoCsBuffer overflow in the kernel in FreeBSD 7.3 through 9.0-RC1 allows local users to cause a denial of service (panic) or possibly gain…
- CVE-2011-40662 PoCsSQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via…
- CVE-2011-40741 PoCCross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web…
- CVE-2011-40754 PoCsThe masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the…
- CVE-2011-40892 PoCsThe bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during…
- CVE-2011-40901 PoCSerendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
- CVE-2011-40941 PoCJara 1.6 has a SQL injection vulnerability.
- CVE-2011-40951 PoCJara 1.6 has an XSS vulnerability
- CVE-2011-41064 PoCsTimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload…
- CVE-2011-41073 PoCsThe simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x…
- CVE-2011-41221 PoCDirectory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs…
- CVE-2011-41242 PoCsInput validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of…
- CVE-2011-41252 PoCsA untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute…
- CVE-2011-41262 PoCsRace condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to…
- CVE-2011-41301 PoCUse-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via…
- CVE-2011-41351 PoCMultiple directory traversal vulnerabilities in lmgrd in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Manager) allow remote…
- CVE-2011-41532 PoCsPHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of…
- CVE-2011-41621 PoCThe (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP…
- CVE-2011-41662 PoCsDirectory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration before 2.6.4…
- CVE-2011-41891 PoCThe client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap…
- CVE-2011-41913 PoCsStack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute…
- CVE-2011-42203 PoCsInvestintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to…
- CVE-2011-42213 PoCsUnspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a denial of service…
- CVE-2011-42223 PoCsUnspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service…
- CVE-2011-42733 PoCsMultiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or…
- CVE-2011-42756 PoCsMultiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to…
- CVE-2011-42801 PoCCross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka spikephpcoverage) library, as used in Moodle 2.0.x before 2.0.2 and…
- CVE-2011-43171 PoCThe mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision…
- CVE-2011-43241 PoCThe encode_share_access function in fs/nfs/nfs4xdr.c in the Linux kernel before 2.6.29 allows local users to cause a denial of service…
- CVE-2011-43331 PoCMultiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrary web script or…
- CVE-2011-43341 PoCedit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload…
- CVE-2011-43351 PoCMultiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2011-43363 PoCsTiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
- CVE-2011-43372 PoCsStatic code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to…
- CVE-2011-43401 PoCMultiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote…
- CVE-2011-43411 PoCMultiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other versions before…
- CVE-2011-43422 PoCsPHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to…
- CVE-2011-43502 PoCsYaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw…
- CVE-2011-43624 PoCsInteger signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before…
- CVE-2011-43672 PoCsMultiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before…
- CVE-2011-44031 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of…
- CVE-2011-44042 PoCsThe default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and…
- CVE-2011-44152 PoCsThe ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif…
- CVE-2011-44311 PoCDirectory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary…
- CVE-2011-44481 PoCSQL injection vulnerability in actions/usersettings/usersettings.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to execute…
- CVE-2011-44492 PoCsactions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are…
- CVE-2011-44501 PoCDirectory traversal vulnerability in handlers/files.xml/files.xml.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to read or…
- CVE-2011-44512 PoCslibs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to write arbitrary PHP…
- CVE-2011-44521 PoCCross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to hijack…
- CVE-2011-44535 PoCsThe PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP…
- CVE-2011-44541 PoCMultiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web script or HTML…
- CVE-2011-44551 PoCMultiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2011-44961 PoCBuffer overflow in Aviosoft DTV Player 1.0.1.2 allows remote attackers to execute arbitrary code via a crafted .plf (aka playlist) file.
- CVE-2011-45181 PoCDirectory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to…
- CVE-2011-45191 PoCStack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service…
- CVE-2011-45201 PoCHeap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service…
- CVE-2011-45291 PoCMultiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow remote attackers to execute arbitrary…
- CVE-2011-45301 PoCSiemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote…
- CVE-2011-45311 PoCSiemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer…
- CVE-2011-45321 PoCAbsolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll in the graphical user interface in…
- CVE-2011-45353 PoCsBuffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer…
- CVE-2011-45401 PoCMultiple cross-site scripting (XSS) vulnerabilities in AtMail Open (aka AtMail Open-Source edition) 1.04 allow remote attackers to inject…
- CVE-2011-45411 PoCCross-site scripting (XSS) vulnerability in index.php in Hastymail2 2.1.1 before RC2 allows remote attackers to inject arbitrary web…
- CVE-2011-45422 PoCsHastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] parameter in a mailbox…
- CVE-2011-45444 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Prestashop before 1.5 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2011-45451 PoCCRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote attackers to inject arbitrary HTTP headers and…
- CVE-2011-45511 PoCCross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote…
- CVE-2011-45582 PoCsTiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.
- CVE-2011-45591 PoCSQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL…
- CVE-2011-45611 PoCCross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2011-45641 PoCCross-site scripting (XSS) vulnerability in the admin script in Active CMS 1.2 allows remote attackers to inject arbitrary web script or…
- CVE-2011-45671 PoCCross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart before 1.5…
- CVE-2011-45692 PoCsSQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to execute arbitrary…
- CVE-2011-45702 PoCsSQL injection vulnerability in the Time Returns (com_timereturns) component 2.0 and possibly earlier versions for Joomla! allows remote…
- CVE-2011-45711 PoCSQL injection vulnerability in the Estate Agent (com_estateagent) component for Joomla! allows remote attackers to execute arbitrary SQL…
- CVE-2011-45722 PoCsCross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions…
- CVE-2011-45951 PoCPretty-Link WordPress plugin 1.5.2 has XSS
- CVE-2011-45971 PoCThe SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2 uses…
- CVE-2011-46131 PoCThe X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X,…
- CVE-2011-46141 PoCPHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x…
- CVE-2011-46182 PoCsCross-site scripting (XSS) vulnerability in advancedtext.php in Advanced Text Widget plugin before 2.0.2 for WordPress allows remote…
- CVE-2011-46202 PoCsBuffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows…
- CVE-2011-46241 PoCCross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress…
- CVE-2011-46402 PoCsDirectory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to read arbitrary…
- CVE-2011-46423 PoCsmappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python classes, which…
- CVE-2011-46432 PoCsMultiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitrary files via a ..…
- CVE-2011-46442 PoCsSplunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that…
- CVE-2011-46703 PoCsMultiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arbitrary web script…
- CVE-2011-46713 PoCsSQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress…
- CVE-2011-46722 PoCsMultiple SQL injection vulnerabilities in Valid tiny-erp 1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the…
- CVE-2011-46732 PoCsSQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL…
- CVE-2011-46742 PoCsSQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows remote attackers to…
- CVE-2011-46841 PoCOpera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to…
- CVE-2011-47091 PoCMultiple cross-site scripting (XSS) vulnerabilities in Hotaru.php in the Search plugin 1.3 for Hotaru CMS allow remote attackers to inject…
- CVE-2011-47102 PoCsMultiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2011-47121 PoCDirectory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an…
- CVE-2011-47132 PoCsDirectory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arbitrary files via a…
- CVE-2011-47143 PoCsDirectory traversal vulnerability in Virtual Vertex Muster before 6.20 allows remote attackers to read arbitrary files via a \..…
- CVE-2011-47152 PoCsDirectory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and…
- CVE-2011-47164 PoCsDirectory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read arbitrary files…
- CVE-2011-47171 PoCDirectory traversal vulnerability in zFTPServer Suite 6.0.0.52 allows remote authenticated users to delete arbitrary directories via a…
- CVE-2011-47201 PoCHillstone HS TFTP Server 1.3.2 allows remote attackers to cause a denial of service (daemon crash) via a long filename in a (1) RRQ or (2)…
- CVE-2011-47223 PoCsDirectory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via…
- CVE-2011-47251 PoCMultiple SQL injection vulnerabilities in the Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 allow remote…
- CVE-2011-47261 PoCMultiple cross-site scripting (XSS) vulnerabilities in the Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18…
- CVE-2011-47271 PoCThe Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is intended…
- CVE-2011-47281 PoCThe Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not set the secure flag for a cookie in an https…
- CVE-2011-47291 PoCThe Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not include the HTTPOnly flag in a Set-Cookie…
- CVE-2011-47301 PoCThe Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 generates a password form field without disabling the…
- CVE-2011-47311 PoCThe Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 includes an RFC 1918 IP address within a web page,…
- CVE-2011-47321 PoCThe Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 omits the Content-Type header's charset parameter for…
- CVE-2011-47331 PoCThe Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 sends incorrect Content-Type headers for certain…
- CVE-2011-47451 PoCMultiple cross-site scripting (XSS) vulnerabilities in the billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 allow remote…
- CVE-2011-47461 PoCThe billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not disable the SSL 2.0 protocol, which makes it easier for…
- CVE-2011-47471 PoCThe billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not prevent the use of weak ciphers for SSL sessions, which…
- CVE-2011-47481 PoCThe billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 has web pages containing e-mail addresses that are not intended for…
- CVE-2011-47491 PoCThe billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete…
- CVE-2011-47761 PoCMultiple cross-site scripting (XSS) vulnerabilities in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allow remote…
- CVE-2011-47771 PoCCross-site scripting (XSS) vulnerability in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Panel 10.4.4_build20111103.18…
- CVE-2011-47862 PoCsA certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an…
- CVE-2011-47892 PoCsStack-based buffer overflow in magentservice.exe in the server in HP LoadRunner 11.00 before patch 4 allows remote attackers to execute…
- CVE-2011-48002 PoCsDirectory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary…
- CVE-2011-48012 PoCsSQL injection vulnerability in akeyActivationLogin.do in Authenex Web Management Control in Authenex Strong Authentication System (ASAS)…
- CVE-2011-48023 PoCsMultiple SQL injection vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote authenticated users to execute arbitrary SQL…
- CVE-2011-48032 PoCsSQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL…
- CVE-2011-48042 PoCsDirectory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attackers to read…
- CVE-2011-48062 PoCsMultiple cross-site scripting (XSS) vulnerabilities in main.php in phpAlbum 0.4.1.16 and earlier allow remote attackers to inject…
- CVE-2011-48072 PoCsDirectory traversal vulnerability in main.php in phpAlbum 0.4.1.16 and earlier allows remote attackers to read arbitrary files via a ..…
- CVE-2011-48082 PoCsSQL injection vulnerability in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allows remote attackers to execute…
- CVE-2011-48092 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allow remote…
- CVE-2011-48102 PoCsMultiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read arbitrary files via…
- CVE-2011-48112 PoCsSQL injection vulnerability in pokaz_podkat.php in BestShopPro allows remote attackers to execute arbitrary SQL commands via the str…
- CVE-2011-48122 PoCsCross-site scripting (XSS) vulnerability in nowosci.php in BestShopPro allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2011-48132 PoCsDirectory traversal vulnerability in clientarea.php in WHMCompleteSolution (WHMCS) 3.x.x allows remote attackers to read arbitrary files…
- CVE-2011-48141 PoCMultiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote attackers to inject arbitrary…
- CVE-2011-48233 PoCsMultiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute…
- CVE-2011-48258 PoCsStatic code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2,…
- CVE-2011-48282 PoCsUnrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute…
- CVE-2011-48292 PoCsSQL injection vulnerability in the com_listing component in Barter Sites component 1.3 for Joomla! allows remote attackers to execute…
- CVE-2011-48302 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the com_listing component in Barter Sites component 1.3 for Joomla! allow remote…
- CVE-2011-48312 PoCsDirectory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to read arbitrary…
- CVE-2011-48322 PoCsDirectory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allows remote attackers…
- CVE-2011-48331 PoCMultiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4…
- CVE-2011-48341 PoCThe GetInstalledPackages function in the configuration tool in HP Application Lifestyle Management (ALM) 11 on AIX, HP-UX, and Solaris…
- CVE-2011-48351 PoCDirectory traversal vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to access arbitrary files via…
- CVE-2011-48361 PoCCross-site scripting (XSS) vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to inject arbitrary web…
- CVE-2011-48371 PoCCross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack…
- CVE-2011-48471 PoCSQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to execute…
- CVE-2011-48481 PoCThe Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes a submitted password within an HTTP response body, which…
- CVE-2011-48491 PoCThe Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not set the secure flag for a cookie in an https session, which…
- CVE-2011-48501 PoCThe Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not include the HTTPOnly flag in a Set-Cookie header for a cookie,…
- CVE-2011-48511 PoCThe Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocomplete…
- CVE-2011-48521 PoCThe Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates web pages containing external links in response to GET…
- CVE-2011-48531 PoCThe Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes an RFC 1918 IP address within a web page, which allows remote…
- CVE-2011-48541 PoCThe Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding…
- CVE-2011-48551 PoCThe Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Content-Type header's charset parameter for certain…
- CVE-2011-48561 PoCThe Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might…
- CVE-2011-48582 PoCsApache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the…
- CVE-2011-48628 PoCsBuffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2…
- CVE-2011-48711 PoCOpen Automation Software OPC Systems.NET before 5.0 allows remote attackers to cause a denial of service via a malformed .NET RPC packet…
- CVE-2011-48722 PoCsMultiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation…
- CVE-2011-48752 PoCsStack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA…
- CVE-2011-48762 PoCsDirectory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka…
- CVE-2011-48772 PoCsHmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort…
- CVE-2011-48782 PoCsDirectory traversal vulnerability in miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3;…
- CVE-2011-48792 PoCsminiweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2…
- CVE-2011-48801 PoCDirectory traversal vulnerability in the web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to read…
- CVE-2011-48811 PoCThe web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly check return values from functions, which allows…
- CVE-2011-48821 PoCThe web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to cause a denial of service (application exit)…
- CVE-2011-48831 PoCThe web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly validate values in HTTP requests, which allows remote…
- CVE-2011-48856 PoCsPHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which…
- CVE-2011-48982 PoCswp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests…
- CVE-2011-48992 PoCswp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database…
- CVE-2011-49061 PoCTiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
- CVE-2011-49083 PoCsTinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
- CVE-2011-49091 PoCMultiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2011-49151 PoCfs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.
- CVE-2011-49161 PoCLinux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.
- CVE-2011-49171 PoCIn the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.
- CVE-2011-49182 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Elxis CMS 2009.2, 2009.3 and 2009.3 Aphrodite before revision 2684 allow remote…
- CVE-2011-49262 PoCsCross-site scripting (XSS) vulnerability in adminimize/adminimize_page.php in the Adminimize plugin before 1.7.22 for WordPress allows…
- CVE-2011-49292 PoCsUnspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute…
- CVE-2011-49381 PoCMultiple cross-site scripting (XSS) vulnerabilities in Ariadne 2.7.6 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2011-49561 PoCCross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2011-49571 PoCThe make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to…
- CVE-2011-49581 PoCCross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6…
- CVE-2011-49691 PoCCross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to…
- CVE-2011-49712 PoCsMultiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4)…