Multiple cross-site scripting (XSS) vulnerabilities in register.php in Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) login and (2) mail_address par…
Remote code execution vulnerability in Zeroboard 4.1 PL7 via a crafted HTTP parameter name in lib.php, possibly related to now_connect.php.
Multiple SQL injection vulnerabilities in PHP-Quick-Arcade (PHPQA) 3.0.21 allow remote attackers to execute arbitrary SQL commands via the (1) phpqa_user_c parameter to Arcade.php and the (2) id param…
Cross-site scripting (XSS) vulnerability in User/User_ChkLogin.asp in PowerEasy 2006 and PowerEasy SiteWeaver 6.8 allows remote attackers to inject arbitrary web script or HTML via the ComeUrl paramet…
Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) Joomla! extension 1.3 that allows remote attackers to read arbitrary files via a .. (dot dot) in the controller param…
A vulnerability in Google Chrome's Google URL Parsing Library (GURL) before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Google Chrome prior to version 4.1.249.1064 contains a vulnerability in HTML5 media handling that could allow remote attackers to cause a denial of service via memory corruption and potentially other …
Directory traversal vulnerability in the Joomla! Ultimate Portfolio component (com_ultimateportfolio) version 1.0 that allows remote attackers to read arbitrary files via .. in the controller paramete…
Directory traversal vulnerability in the Joomla! SmartSite (com_smartsite) component version 1.0.0 allows remote attackers to read arbitrary files via a .. sequence in the controller parameter to inde…
Cross-site scripting (XSS) vulnerability in acpmoderate.php in PHP-Quick-Arcade (PHPQA) 3.0.21 allows remote attackers to inject arbitrary web script or HTML via the serv parameter.
CVE-2010-1665: Google Chrome before 4.1.249.1064 does not properly handle fonts, which allows remote attackers to cause a denial of service (memory corruption) and possibly have unspecified other impa…
SQL injection vulnerability in the Airiny ABC (com_abc) component 1.1.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sectionid parameter in an abc action to index.php.…
SQL injection vulnerability in CLScript Classifieds Script's help-details.php allows remote attackers to execute arbitrary SQL commands via the hpId parameter.
Directory traversal (local file inclusion) vulnerability in Joomla!'s Graphics (com_graphics) extension, allowing remote attackers to include and execute arbitrary local files via a .. sequence in the…
Directory traversal vulnerability in Help Center Live's HelpCenter module (HCL) affecting versions 2.0.6 and 2.1.7, allowing remote attackers to read arbitrary files via a .. (dot dot) in the file par…
Multiple SQL injection vulnerabilities in Infocus Real Estate Enterprise Edition's system_member_login.php allow remote attackers to execute arbitrary SQL commands via the username (login) and passwor…
IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x before 7.0.0.11, when the -trace option (debugging mode) is enabled, executes debugging statements that p…
Information disclosure vulnerability in IBM WebSphere Application Server (WAS) where SIP trace logging combined with Basic authentication can expose entire SIP messages via trace logs in affected vers…