Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-4332

Published Nov 23, 2011

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.6.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4321

Published Nov 23, 2011

The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak random numbers, which makes it easier for remote attackers to change the passwords of arbitrary users vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5062

Published Nov 23, 2011

SQL injection vulnerability in search.php in MH Products kleinanzeigenmarkt allows remote attackers to execute arbitrary SQL commands via the c parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5061

Published Nov 23, 2011

SQL injection vulnerability in index.php in RSStatic allows remote attackers to execute arbitrary SQL commands via the maxarticles parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5060

Published Nov 23, 2011

SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5059

Published Nov 23, 2011

SQL injection vulnerability in index.php in CMScout 2.0.8 allows remote attackers to execute arbitrary SQL commands via the album parameter in a photos action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5058

Published Nov 23, 2011

SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the res_id parameter. NOTE: the provenance of th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5057

Published Nov 23, 2011

SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the tipodoc_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5056

Published Nov 23, 2011

SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the face_id parameter i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5055

Published Nov 23, 2011

SQL injection vulnerability in index.php in Almnzm 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5054

Published Nov 23, 2011

Cross-site scripting (XSS) vulnerability in Special:Login in JAMWiki before 0.8.4 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5053

Published Nov 23, 2011

SQL injection vulnerability in the XOBBIX (com_xobbix) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a prod_des…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5052

Published Nov 23, 2011

Cross-site scripting (XSS) vulnerability in admin/components.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the val[] parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5051

Published Nov 23, 2011

Cross-site scripting (XSS) vulnerability in admin/core/admin_func.php in razorCMS 1.0 stable allows remote attackers to inject arbitrary web script or HTML via the content paramet…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5050

Published Nov 23, 2011

Cross-site scripting (XSS) vulnerability in jsp/admin/tools/remote_share.jsp in ManageEngine ADManager Plus 4.4.0 allows remote attackers to inject arbitrary web script or HTML vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5049

Published Nov 23, 2011

SQL injection vulnerability in events.php in Zabbix 1.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the nav_time parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5048

Published Nov 23, 2011

Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inje…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5047

Published Nov 23, 2011

SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5046

Published Nov 23, 2011

Cross-site scripting (XSS) vulnerability in admin.php in ecoCMS allows remote attackers to inject arbitrary web script or HTML via the p parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4507

Published Nov 22, 2011

The D-Link DIR-685 router, when certain WPA and WPA2 configurations are used, does not maintain an encrypted wireless network during transfer of a large amount of network traffic,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4504

Published Nov 22, 2011

The UPnP IGD implementation in the Pseudo ICS UPnP software on the ZyXEL P-330W allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping actio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4503

Published Nov 22, 2011

The UPnP IGD implementation in Broadcom Linux on the Sitecom WL-111 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 401-425 of 4,150 CVEsPage 17 of 166