Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2010-5045

Published Nov 2, 2011

Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbitrary web script or HTML via the catid parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5044

Published Nov 2, 2011

SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remote authenticated users, with Public Back-end privileges, to…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5039

Published Nov 2, 2011

SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid paramete…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5038

Published Nov 2, 2011

PHP remote file inclusion vulnerability in contact/contact.php in Groone's Simple Contact Form allows remote attackers to execute arbitrary PHP code via a URL in the abspath param…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5036

Published Nov 2, 2011

SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5035

Published Nov 2, 2011

Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5034

Published Nov 2, 2011

SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the planid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5033

Published Nov 2, 2011

SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL commands via the CatDisplay parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5031

Published Nov 2, 2011

Cross-site scripting (XSS) vulnerability in index.php in fileNice 1.1 allows remote attackers to inject arbitrary web script or HTML via the sstring parameter (aka the Search Box)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5030

Published Nov 2, 2011

Cross-site scripting (XSS) vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to inject arbitrary web script or HTML via the lang parameter in a web action.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5029

Published Nov 2, 2011

SQL injection vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the show parameter in a web action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5028

Published Nov 2, 2011

SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5027

Published Nov 2, 2011

Cross-site scripting (XSS) vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the typ…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5026

Published Nov 2, 2011

SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5025

Published Nov 2, 2011

Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to inject arbitrary web script or HTML via the fld_path paramet…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5024

Published Nov 2, 2011

SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, with Read privileges, to execute arbitrary SQL commands via t…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5023

Published Nov 2, 2011

SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5021

Published Nov 2, 2011

SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intGroupID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 551-575 of 4,150 CVEsPage 23 of 166