Skip to main content

Year archive

CVEs published in 2010

Archive summary

4,639 CVEs published in 2010 — 1,019 Critical, 1,102 High, 2,241 Medium, 277 Low, 0 Unrated.

CVE-2009-4628

Published Jan 18, 2010

SQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4627

Published Jan 18, 2010

Directory traversal vulnerability in sources/_template_parser.php in Moa Gallery 1.2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the p_file…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4626

Published Jan 18, 2010

Directory traversal vulnerability in menu.php in phpNagios 1.2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the conf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4624

Published Jan 18, 2010

SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2005…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4623

Published Jan 18, 2010

Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the ACS_path parameter to (1) i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4622

Published Jan 18, 2010

PHP remote file inclusion vulnerability in admin/admin_news_bot.php in Drunken:Golem Gaming Portal 0.5.1 alpha 2 allows remote attackers to execute arbitrary PHP code via a URL in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4621

Published Jan 18, 2010

SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4620

Published Jan 18, 2010

SQL injection vulnerability in the Joomloc (com_joomloc) component 1.0 for Joomla allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4619

Published Jan 18, 2010

SQL injection vulnerability in the Lucy Games (com_lucygames) component 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a g…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4618

Published Jan 18, 2010

Multiple SQL injection vulnerabilities in Tourism Script Bus Script allow remote attackers to execute arbitrary SQL commands via the sitetext_id parameter to (1) aboutus.php and (…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4616

Published Jan 18, 2010

Cross-site scripting (XSS) vulnerability in search.php in MYRE Holiday Rental Manager allows remote attackers to inject arbitrary web script or HTML via the cat_id1 parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4615

Published Jan 18, 2010

SQL injection vulnerability in review.php in MYRE Holiday Rental Manager allows remote attackers to execute arbitrary SQL commands via the link_id parameter in a show_review actio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4614

Published Jan 18, 2010

Multiple PHP remote file inclusion vulnerabilities in Moa Gallery 1.2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the MOA_PATH parameter to (1)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0356

Published Jan 18, 2010

Stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control in MoviePlayer.ocx 6.8.0.0 in Viscom Software Movie Player Pro SDK ActiveX 6.8 allows remote attac…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0349

Published Jan 15, 2010

Cross-site scripting (XSS) vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: this…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0348

Published Jan 15, 2010

Directory traversal vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to read arbitrary files via unknown vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0347

Published Jan 15, 2010

Cross-site scripting (XSS) vulnerability in the VD / Geomap (vd_geomap) extension 0.3.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via un…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0346

Published Jan 15, 2010

Cross-site scripting (XSS) vulnerability in the Tip many friends (mimi_tipfriends) extension 0.0.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0345

Published Jan 15, 2010

Cross-site scripting (XSS) vulnerability in the Majordomo extension 1.1.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vect…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0344

Published Jan 15, 2010

SQL injection vulnerability in the zak_store_management extension 1.0.0 and earlier TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0343

Published Jan 15, 2010

SQL injection vulnerability in the Clan Users List (pb_clanlist) extension 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0342

Published Jan 15, 2010

SQL injection vulnerability in the Reports for Job (job_reports) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified ve…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 4,426-4,450 of 4,639 CVEsPage 178 of 186