Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2010-5020

Published Nov 2, 2011

SQL injection vulnerability in index.php in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5019

Published Nov 2, 2011

SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arbitrary SQL commands via the alb parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5018

Published Nov 2, 2011

Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5017

Published Nov 2, 2011

SQL injection vulnerability in stats.php in Elite Gaming Ladders 3.0 allows remote attackers to execute arbitrary SQL commands via the account parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5016

Published Nov 2, 2011

SQL injection vulnerability in matchdb.php in Elite Gaming Ladders 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the match parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5015

Published Nov 2, 2011

SQL injection vulnerability in view_photo.php in 2daybiz Network Community Script allows remote attackers to execute arbitrary SQL commands via the alb parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5014

Published Nov 2, 2011

SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5012

Published Nov 2, 2011

SQL injection vulnerability in new.php in DaLogin 2.2 and 2.2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are ob…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5011

Published Nov 2, 2011

SQL injection vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to execute arbitrary SQL commands via the session parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5010

Published Nov 2, 2011

Cross-site scripting (XSS) vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to inject arbitrary web script or HTML via the session param…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5009

Published Nov 2, 2011

SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5008

Published Nov 2, 2011

SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to execute arbitrary SQL commands via the ContactID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5007

Published Nov 2, 2011

Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers to inject arbitrary web script or HTML via the mid paramet…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5006

Published Nov 2, 2011

SQL injection vulnerability in googlemap/index.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the cat1 parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5005

Published Nov 2, 2011

Cross-site scripting (XSS) vulnerability in members/profileCommentsResponse.php in Rayzz Photoz allows remote attackers to inject arbitrary web script or HTML via the profileComme…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5004

Published Nov 2, 2011

SQL injection vulnerability in searchvote.php in 2daybiz Polls (aka Advanced Poll) Script allows remote attackers to execute arbitrary SQL commands via the category parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5000

Published Nov 2, 2011

SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the myusername parameter (aka User…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4998

Published Nov 2, 2011

PHP remote file inclusion vulnerability in ardeaCore/lib/core/ardeaInit.php in ardeaCore PHP Framework 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4997

Published Nov 2, 2011

SQL injection vulnerability in index.php in OlyKit Swoopo Clone 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter in a product action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4075

Published Nov 2, 2011

The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4074

Published Nov 2, 2011

Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3320

Published Nov 2, 2011

Cross-site scripting (XSS) vulnerability in the Web Administrator component in GE Intelligent Platforms Proficy Historian 4.x and earlier allows remote attackers to inject arbitra…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3167

Published Nov 2, 2011

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1210.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 576-600 of 4,150 CVEsPage 24 of 166