/
cyberknowledge
/
CVE
ОбзорДокументацияВойти
/
cyberknowledge
/
CVE
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
CI/CD
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/nuclei_templates.csv
101 строка47 KB

Zeros312

Rename sample/ to samples/; remove README from samples
30 июн 2026, 21:21
30 июн 2026, 21:2183c96cb
100 строк
CVE-2000-0114
Microsoft FrontPage Extensions - Information Disclosure
medium
Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.
5.30
http/cves/2000/CVE-2000-0114.yaml
2293076cdb5d79beea73ef1ec05f4e798618f8e606d987c093770ad7bd6338cd
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2000-0760
Jakarta Tomcat 3.1 and 3.0 - Information Disclosure
medium
Jakarta Tomcat 3.1 and 3.0 under Apache contain a vulnerability in the Snoop servlet that reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension, exploit requires remote access.
6.40
http/cves/2000/CVE-2000-0760.yaml
b237c6362ba93981b9ea2dab3b07e626358baad62b871c6a707c28868cd13e00
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2001-0537
Cisco IOS HTTP Configuration - Authentication Bypass
critical
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.
9.30
http/cves/2001/CVE-2001-0537.yaml
d6d6e77a5fd43e0f542cd60617d07bf3a039330dcc0d818294483b4a9a93b482
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2002-1131
SquirrelMail 1.2.6/1.2.7 - Cross-Site Scripting
high
The Virtual Keyboard plugin for SquirrelMail 1.2.6/1.2.7 is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
7.50
http/cves/2002/CVE-2002-1131.yaml
c7e9a484a29636fa8cf2ef229e0ac97627603420274e16fd8f4cae6fc528f750
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2004-0519
SquirrelMail 1.4.x - Folder Name Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.
6.80
http/cves/2004/CVE-2004-0519.yaml
a7823247cf2a4297c741940bbd160a56baba13297f2817412371826c6058c6f6
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2004-1965
Open Bulletin Board (OpenBB) v1.0.6 - Open Redirect/XSS
medium
Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) redirect parameter to member.php, (2) to parameter to myhome.php (3) TID parameter to post.php, or (4) redirect parameter to index.php.
4.30
http/cves/2004/CVE-2004-1965.yaml
406fc03c9c94ed7972a535e956c23f5ea02ed6eb67aaa7186c7d09607e43cb2b
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2005-2428
Lotus Domino R5 and R6 WebMail - Information Disclosure
medium
Lotus Domino R5 and R6 WebMail with 'Generate HTML for all fields' enabled (which is by default) allows remote attackers to read the HTML source to obtain sensitive information including the password hash in the HTTPPassword field, the password change date in the HTTPPasswordChangeDate field, and the client Lotus Domino release in the ClntBld field (a different vulnerability than CVE-2005-2696).
5.00
http/cves/2005/CVE-2005-2428.yaml
a0f5f769d10adefb84b29d636c6de51da9e4f0dec3511b0d905bc529e5a98d43
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2005-3128
SquirrelMail Address Add 1.4.2 - Cross-Site Scripting
medium
SquirrelMail Address Add 1.4.2 plugin contains a cross-site scripting vulnerability. It fails to properly sanitize user-supplied input, thus allowing an attacker to execute arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
5.40
http/cves/2005/CVE-2005-3128.yaml
1c623ee9be0651d23b03632d9c0115a82b1a48274c04d3c67af17b6a772571c8
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2005-3344
Horde Groupware Unauthenticated Admin Access
critical
Horde Groupware contains an administrative account with a blank password, which allows remote attackers to gain access.
10.00
http/cves/2005/CVE-2005-3344.yaml
e92b596852cda38a2a738732fc41caaffc77281224e8daf6378f28b8316a27c5
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2005-3634
SAP Web Application Server 6.x/7.0 - Open Redirect
medium
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.
5.00
http/cves/2005/CVE-2005-3634.yaml
f7aa4e41d4c0c315e8710858b205f8704f653d10f73dce55d139c07f9b9eafa7
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2005-4385
Cofax <=2.0RC3 - Cross-Site Scripting
medium
Cofax 2.0 RC3 and earlier contains a cross-site scripting vulnerability in search.htm which allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.
4.30
http/cves/2005/CVE-2005-4385.yaml
ea383b693c7e8e23d9fdd534dc92d951a03b5d6ea0741b7f798f029c8e2ddda8
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2006-1681
Cherokee HTTPD <=0.5 - Cross-Site Scripting
medium
Cherokee HTTPD 0.5 and earlier contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated.
4.30
http/cves/2006/CVE-2006-1681.yaml
13e0bcec8dbfae70e2d8c9937d25aaf8358c8b10d10e79ca6eb56e11629ecbc7
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2006-2842
Squirrelmail <=1.4.6 - Local File Inclusion
high
SquirrelMail 1.4.6 and earlier versions are susceptible to a PHP local file inclusion vulnerability in functions/plugin.php if register_globals is enabled and magic_quotes_gpc is disabled. This allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter.
7.50
http/cves/2006/CVE-2006-2842.yaml
4a74e1ea4fc517cc67870de30242689e97081a7eed2cfc90974be29f71dac8c8
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2006-3392
Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure
medium
Webmin before 1.290 and Usermin before 1.220 contain a path traversal caused by calling the simplify_path function before decoding HTML, letting remote attackers read arbitrary files, exploit requires sending crafted '..%01' sequences.
5.00
http/cves/2006/CVE-2006-3392.yaml
47fda3ba4f0b726191af20170292b2ca65862afe66a02da8b04714f88a00694f
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2007-0885
Jira Rainbow.Zen - Cross-Site Scripting
medium
Jira Rainbow.Zen contains a cross-site scripting vulnerability via Jira/secure/BrowseProject.jspa which allows remote attackers to inject arbitrary web script or HTML via the id parameter.
6.80
http/cves/2007/CVE-2007-0885.yaml
da3e3ee590137c4d1390c1e0ce35ab326f76e336ec37340b0009b07c5e895dd6
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2007-2449
Apache Tomcat 4.x-7.x - Cross-Site Scripting
medium
Apache Tomcat 4.x through 7.x contains a cross-site scripting vulnerability which an attacker can use to execute arbitrary script in the browser of an unsuspecting user in the context of the affected site.
7.20
http/cves/2007/CVE-2007-2449.yaml
a7f0a272dec58e4d33cc218437a70bfea0b2d7ff490968ff56ce6eb3409e27cd
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2007-3010
Alcatel-Lucent OmniPCX - Remote Command Execution
critical
The OmniPCX web interface has a script "masterCGI" with a remote command execution vulnerability via the "user" parameter.
10.00
http/cves/2007/CVE-2007-3010.yaml
0492b759a8d8284045ba0988608e5146f77fa9ac7c6ba8df67ffd7be71be5cb0
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2007-4504
Joomla! RSfiles <=1.0.2 - Local File Inclusion
medium
Joomla! RSfiles 1.0.2 and earlier is susceptible to local file inclusion in index.php in the RSfiles component (com_rsfiles). This could allow remote attackers to arbitrarily read files via a .. (dot dot) in the path parameter in a files.display action.
5.00
http/cves/2007/CVE-2007-4504.yaml
4bd958b9974ea07c424e82cdf02b64a4c4481aa0c0e890d62e28c5f5832d0bd8
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2007-4556
OpenSymphony XWork/Apache Struts2 - Remote Code Execution
medium
Apache Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via for"m input beginning with a "%{" sequence and ending with a "}" character.
6.80
http/cves/2007/CVE-2007-4556.yaml
78e7607b57054674f5538bf4cc8be207f5627ff2fa2dde2c49778c7b2c8b66cf
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2007-5728
phpPgAdmin <=4.1.1 - Cross-Site Scripting
medium
phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, is vulnerable to cross-site scripting and allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php, which are different vectors than CVE-2007-2865.
4.30
http/cves/2007/CVE-2007-5728.yaml
1b8cd2ba3249d81e279683bf0c0ff06f3a5b5fc25d4aafd9063e4a9e56dcb300
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-1059
WordPress Sniplets 1.1.2 - Local File Inclusion
high
PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter.
7.50
http/cves/2008/CVE-2008-1059.yaml
a43e83ef89ba87c7f1115153b0657b5ec34562870762b3e69790b2e88a110435
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-1061
WordPress Sniplets <=1.2.2 - Cross-Site Scripting
medium
WordPress Sniplets 1.1.2 and 1.2.2 plugin contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary web script or HTML via the text parameter to warning.php, notice.php, and inset.php in view/sniplets/, and possibly modules/execute.php; via the url parameter to view/admin/submenu.php; and via the page parameter to view/admin/pager.php.
4.30
http/cves/2008/CVE-2008-1061.yaml
6439729ff89e5e03982cbd25b971615a3ce996b2848ee35a436b1cdab24b724b
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-1547
Microsoft OWA Exchange Server 2003 - 'redir.asp' Open Redirection
medium
Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.
4.30
http/cves/2008/CVE-2008-1547.yaml
d6937f15c324eceb6597653d2c17b074308f1253c54be264b22c8b7b856e5f7e
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-2398
AppServ Open Project <=2.5.10 - Cross-Site Scripting
medium
AppServ Open Project 2.5.10 and earlier contains a cross-site scripting vulnerability in index.php which allows remote attackers to inject arbitrary web script or HTML via the appservlang parameter.
4.30
http/cves/2008/CVE-2008-2398.yaml
c8bbf71e1084cc6c6ee0fd59b243f538a041261371d73de9cd35770eced50bf5
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-2650
CMSimple 3.1 - Local File Inclusion
medium
CMSimple 3.1 is susceptible to local file inclusion via cmsimple/cms.php when register_globals is enabled which allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sl parameter to index.php. NOTE: this can be leveraged for remote file execution by including adm.php and then invoking the upload action. NOTE: on 20080601, the vendor patched 3.1 without changing the version number.
6.80
http/cves/2008/CVE-2008-2650.yaml
1f27767429188582514b05d7f401426470c69240ccc44ebadc1fad592680e1fc
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-4668
Joomla! Image Browser 0.1.5 rc2 - Local File Inclusion
critical
Joomla! Image Browser 0.1.5 rc2 is susceptible to local file inclusion via com_imagebrowser which could allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder parameter to index.php.
9.00
http/cves/2008/CVE-2008-4668.yaml
e8975d9205fded101a2412ca0c21a375772fb1a097fd8191ced51a1511ca4d2c
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-4764
Joomla! <=2.0.0 RC2 - Local File Inclusion
medium
Joomla! 2.0.0 RC2 and earlier are susceptible to local file inclusion in the eXtplorer module (com_extplorer) that allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action.
5.00
http/cves/2008/CVE-2008-4764.yaml
e2512300505218d1a6f01ef954057af020955b77d807548cc9aa7c09938d86da
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-5587
phpPgAdmin <=4.2.1 - Local File Inclusion
medium
phpPgAdmin 4.2.1 is vulnerable to local file inclusion in libraries/lib.inc.php when register globals is enabled. Remote attackers can read arbitrary files via a .. (dot dot) in the _language parameter to index.php.
4.30
http/cves/2008/CVE-2008-5587.yaml
5f46be67cebf29835395b517d3a160d58628c8012f6bca12f29a633c5c0a5579
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-6080
Joomla! ionFiles 4.4.2 - Local File Inclusion
medium
Joomla! ionFiles 4.4.2 is susceptible to local file inclusion in download.php in the ionFiles (com_ionfiles) that allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
5.00
http/cves/2008/CVE-2008-6080.yaml
b5adb0b863f70291492e8dbbdf9d4f83990b2bfe3bd28031b117b7ae219eec99
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-6172
Joomla! Component RWCards 3.0.11 - Local File Inclusion
medium
A directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla! when magic_quotes_gpc is disabled allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the img parameter.
6.80
http/cves/2008/CVE-2008-6172.yaml
a5b7217614cecabfe8f0e99a971f1cfd860ef109dae208ffb6debf593d5c53a1
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-6222
Joomla! ProDesk 1.0/1.2 - Local File Inclusion
medium
Joomla! Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter to index.php.
5.00
http/cves/2008/CVE-2008-6222.yaml
77ecd943908c957ffac1aefd0f1f476fa8f6bf30c9278ed756282919b9804a06
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-6465
Parallels H-Sphere 3.0.0 P9/3.1 P1 - Cross-Site Scripting
medium
Parallels H-Sphere 3.0.0 P9 and 3.1 P1 contains multiple cross-site scripting vulnerabilities in login.php in webshell4. An attacker can inject arbitrary web script or HTML via the err, errorcode, and login parameters, thus allowing theft of cookie-based authentication credentials and launch of other attacks.
4.30
http/cves/2008/CVE-2008-6465.yaml
4517a7692d9d1ad6bd9f21073b9a287983c181076b814fb362791564dd5879b8
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-6668
nweb2fax <=0.2.7 - Local File Inclusion
medium
nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via the id parameter submitted to comm.php and the var_filename parameter submitted to viewrq.php.
5.00
http/cves/2008/CVE-2008-6668.yaml
4306c5ec0f5d9435c2aab116a5be74f2478ecb2b90427f80a07c96b312058d11
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-6982
Devalcms 1.4a - Cross-Site Scripting
medium
Devalcms 1.4a contains a cross-site scripting vulnerability in the currentpath parameter of the index.php file.
4.30
http/cves/2008/CVE-2008-6982.yaml
d708da967c3a8e63f94d4aafaa10b083f18a9649f8e8ff9ccb58c31efd8ae844
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2008-7269
UC Gateway Investment SiteEngine v5.0 - Open Redirect
medium
Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the forward parameter in a logout action.
5.80
http/cves/2008/CVE-2008-7269.yaml
0b26d98e4378f67c5e363e0bdd586499b6814d05b13a732167de4ec8d2d5d89a
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-0347
Autonomy Ultraseek - Open Redirect
medium
Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.
5.80
http/cves/2009/CVE-2009-0347.yaml
4a189d4fe568bda15175e069b9fcb9384e3c5c1395eaa19950389986e9720b48
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-0545
ZeroShell <= 1.0beta11 Remote Code Execution
critical
ZeroShell 1.0beta11 and earlier via cgi-bin/kerbynet allows remote attackers to execute arbitrary commands through shell metacharacters in the type parameter in a NoAuthREQ x509List action.
10.00
http/cves/2009/CVE-2009-0545.yaml
983d2c59a29df18655bd5cccb3a53085b7682bd41d482a2d1182bcd7e7da7ea3
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-0932
Horde/Horde Groupware - Local File Inclusion
medium
Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 are susceptible to local file inclusion in framework/Image/Image.php because it allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.
6.40
http/cves/2009/CVE-2009-0932.yaml
1c42053411b559b3a9f7238af9f43dcf0da058672f988030432727c42ef92516
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-1151
PhpMyAdmin Scripts - Remote Code Execution
high
PhpMyAdmin Scripts 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 are susceptible to a remote code execution in setup.php that allows remote attackers to inject arbitrary PHP code into a configuration file via the save action. Combined with the ability to save files on server, this can allow unauthenticated users to execute arbitrary PHP code.
7.50
http/cves/2009/CVE-2009-1151.yaml
4b9f1475dcd71ca42a137a026a996635843082e5a179d58993b2f44ccee642ca
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-1496
Joomla! Cmimarketplace 0.1 - Local File Inclusion
medium
Joomla! Cmimarketplace 0.1 is susceptible to local file inclusion because com_cmimarketplace allows remote attackers to list arbitrary directories via a .. (dot dot) in the viewit parameter to index.php.
5.00
http/cves/2009/CVE-2009-1496.yaml
6f2ef307565e94c563adead4d9c5bf4aaa88e0d384ab05552909fc1f4265dd48
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-1558
Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusion
high
Cisco Linksys WVC54GCA 1.00R22/1.00R24 is susceptible to local file inclusion in adm/file.cgi because it allows remote attackers to read arbitrary files via a %2e. (encoded dot dot) or an absolute pathname in the next_file parameter.
7.80
http/cves/2009/CVE-2009-1558.yaml
a971d5fa344633084c1a4c07e43559a26ec11bce7ddb0475f4c4de00c222b607
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-1872
Adobe Coldfusion <=8.0.1 - Cross-Site Scripting
medium
Adobe ColdFusion Server 8.0.1 and earlier contain multiple cross-site scripting vulnerabilities which allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.
4.30
http/cves/2009/CVE-2009-1872.yaml
47ef1374245b69e438ddb6f64e18c1554f16efd2dab45a93d234a616a1dff4d5
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-2015
Joomla! MooFAQ 1.0 - Local File Inclusion
high
Joomla! Ideal MooFAQ 1.0 via com_moofaq allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter (local file inclusion).
7.50
http/cves/2009/CVE-2009-2015.yaml
7109a472867694cd877fb1b2576a609ad227c051e51d211d86487a4f0dd27024
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-2100
Joomla! JoomlaPraise Projectfork 2.0.10 - Local File Inclusion
medium
Joomla! JoomlaPraise Projectfork (com_projectfork) 2.0.10 allows remote attackers to read arbitrary files via local file inclusion in the section parameter to index.php.
5.00
http/cves/2009/CVE-2009-2100.yaml
66c2404e98c87752e02d07b3114f7715ae6db1133fdc37c8404dc1d6755d502f
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-3053
Joomla! Agora 3.0.0b - Local File Inclusion
medium
Joomla! Agora 3.0.0b (com_agora) allows remote attackers to include and execute arbitrary local files via local file inclusion in the action parameter to the avatars page, reachable through index.php.
6.80
http/cves/2009/CVE-2009-3053.yaml
c5e4bdeeb39ff9faa7959fbd940531394eb6dbeb77819f1a34d8f160515d3f2c
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-3318
Joomla! Roland Breedveld Album 1.14 - Local File Inclusion
high
Joomla! Roland Breedveld Album 1.14 (com_album) is susceptible to local file inclusion because it allows remote attackers to access arbitrary directories and have unspecified other impact via a .. (dot dot) in the target parameter to index.php.
7.50
http/cves/2009/CVE-2009-3318.yaml
1cec3bdc07e98c8c4795bad5c784ff8064178ca7c478c99ceeedfa1a8f50c18e
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-4202
Joomla! Omilen Photo Gallery 0.5b - Local File Inclusion
high
Joomla! Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.
7.50
http/cves/2009/CVE-2009-4202.yaml
4c8b63bf5d9540e7b5d98b72bb099718aa72563b6ec59a6dc8d00e4a18b1d257
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-4223
KR-Web <=1.1b2 - Remote File Inclusion
high
KR-Web 1.1b2 and prior contain a remote file inclusion vulnerability via adm/krgourl.php, which allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.
7.50
http/cves/2009/CVE-2009-4223.yaml
55dd10b9059acf12beff710233d280eedc6782fa9a171b1395de9bf60112ef87
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-4679
Joomla! Portfolio Nexus - Remote File Inclusion
high
Joomla! Portfolio Nexus 1.5 contains a remote file inclusion vulnerability in the inertialFATE iF (com_if_nexus) component that allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
7.50
http/cves/2009/CVE-2009-4679.yaml
32693928142aa26fae3418e99a04e651fc49e37c1befb45d5021646dd083a9d6
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-5020
AWStats < 6.95 - Open Redirect
medium
An open redirect vulnerability in awredir.pl in AWStats < 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
5.80
http/cves/2009/CVE-2009-5020.yaml
d5692428795c9a6992da36131182b3285514f3fb2875211a7bd3134121966e66
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2009-5114
WebGlimpse 2.18.7 - Directory Traversal
medium
A directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the DOC parameter.
5.00
http/cves/2009/CVE-2009-5114.yaml
798560daf2c4b6a573de489512424e88ef6429645c7bb14c8f9dcad80a170000
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-0157
Joomla! Component com_biblestudy - Local File Inclusion
high
A directory traversal vulnerability in the Bible Study (com_biblestudy) component 6.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter in a studieslist action to index.php.
7.50
http/cves/2010/CVE-2010-0157.yaml
085f3e347367b090fb6b11fbafd2937c9e12c8327f9091e3d09c890882d6895d
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-0219
Apache Axis2 Default Login
critical
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
10.00
http/cves/2010/CVE-2010-0219.yaml
5ee462e71f708590ef100b27509172c7da1e8f4444985c880d1d3373322761d2
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-0467
Joomla! Component CCNewsLetter - Local File Inclusion
medium
A directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.
5.80
http/cves/2010/CVE-2010-0467.yaml
661bf98ff81ff9b07eb52709a7a07d8c32e7ef99715ba39c13155d27b48da6eb
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-0696
Joomla! Component Jw_allVideos - Arbitrary File Retrieval
medium
A directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../.../ (modified dot dot) in the file parameter.
5.00
http/cves/2010/CVE-2010-0696.yaml
fe463a71b9d2e71857a0c7fb488e6c29d7abcb1dc263bd2c19e6cf7d3dd0da25
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-0759
Joomla! Plugin Core Design Scriptegrator - Local File Inclusion
high
A directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allows remote attackers to read, and possibly include and execute, arbitrary files via directory traversal sequences in the files[] parameter.
7.50
http/cves/2010/CVE-2010-0759.yaml
a175d3830aec4d35425010fadd0324f4298e8cad56d9c2d5d8cc239cce3ebe43
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-0942
Joomla! Component com_jvideodirect - Directory Traversal
medium
Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-0942.yaml
de5bd8b83209e28c0dbfd7ce5a3de27f8acf0a700720e4f90b6a6ed3137a897b
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-0943
Joomla! Component com_jashowcase - Directory Traversal
medium
A directory traversal vulnerability in the JA Showcase (com_jashowcase) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a jashowcase action to index.php.
5.00
http/cves/2010/CVE-2010-0943.yaml
e4c0f9bdec4e751eea98b0d90515dc2b0c682626f823613e60bbaa00ed561656
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-0944
Joomla! Component com_jcollection - Directory Traversal
medium
A directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-0944.yaml
1e66e3d13ada191ad9408e1663090a6b64ec74214e7061eaa8dfda018938527c
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-0972
Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusion
high
A directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
7.50
http/cves/2010/CVE-2010-0972.yaml
00d9a05b613e32024cfb22f93dc2a2657d1fb733f70d65e3d9bb06ff5b822561
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-0982
Joomla! Component com_cartweberp - Local File Inclusion
medium
A directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
4.30
http/cves/2010/CVE-2010-0982.yaml
21b0f1ba045cec5b4ecbe82a6b9fdce698aeb0857f0be5275b44deaad872642d
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-0985
Joomla! Component com_abbrev - Local File Inclusion
high
A directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
7.50
http/cves/2010/CVE-2010-0985.yaml
d6721fff7ebc9367548de39d0cb50daaa56c6cc5110aa277df32706b011ccb94
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1056
Joomla! Component com_rokdownloads - Local File Inclusion
medium
A directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
6.80
http/cves/2010/CVE-2010-1056.yaml
fb3933158fab82209a3b9f442895a2db1e0d88b4dbe79ddd4ec9fad687e6a815
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1081
Joomla! Component com_communitypolls 1.5.2 - Local File Inclusion
medium
A directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1081.yaml
f04dd231624b2ed494686e06e9ac0a05f615f58651cec4d1a5ba736091e72fbc
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1217
Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusion
medium
A directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE -- the original researcher states that the affected product is JE Tooltip, not Form Creator; however, the exploit URL suggests that Form Creator is affected.
4.30
http/cves/2010/CVE-2010-1217.yaml
433b458c283a2bf1172ff96290d99b3c4f7384751215a6dc490a2148f4ef3f38
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1219
Joomla! Component com_janews - Local File Inclusion
medium
A directory traversal vulnerability in the JA News (com_janews) component 1.0 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
6.80
http/cves/2010/CVE-2010-1219.yaml
dd4955735b5d7b09bca00f52358838cd27de368ae79315d8379d7b56f339b383
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1302
Joomla! Component DW Graph - Local File Inclusion
medium
A directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1302.yaml
31189db05762488e03488ba29ded4226da03064934445affdcc9e5029e558fab
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1304
Joomla! Component User Status - Local File Inclusion
medium
A directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1304.yaml
3955704d5242ef8fb09f2d9d8512b59c8974fc09b1a6b3474ee367ede0f18326
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1305
Joomla! Component JInventory 1.23.02 - Local File Inclusion
medium
A directory traversal vulnerability in jinventory.php in the JInventory (com_jinventory) component 1.23.02 and possibly other versions before 1.26.03, a module for Joomla!, allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1305.yaml
77886331b647fe5989ec2f6315e06a55679dee32395c02d0af4b416bc91a7c8d
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1306
Joomla! Component Picasa 2.0 - Local File Inclusion
high
A directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
7.50
http/cves/2010/CVE-2010-1306.yaml
9b0aed347c555c607d111a137fb72a43803e202bdf66af1d239f554ed37c5255
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1307
Joomla! Component Magic Updater - Local File Inclusion
medium
A directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1307.yaml
0aceeac56b52eb2e2ee2cde8771c6e4c3d14e8bc02a8d1ab11c2db9e0f9ada2a
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1308
Joomla! Component SVMap 1.1.1 - Local File Inclusion
medium
A directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1308.yaml
180dda0721980f170c374805293850f3df83419b3e4e578eddef7e44285da044
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1312
Joomla! Component News Portal 1.5.x - Local File Inclusion
medium
A directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1312.yaml
654942c363cd9f9e46ee1da438aa9ff426e1f171ebf851cdd7b15ae2c09b3a98
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1313
Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusion
medium
A directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0.12 and 1.0.0.13 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.
4.30
http/cves/2010/CVE-2010-1313.yaml
d7033c23d9e55249c5a0b48ad9cab1e3240150e1cf172bc997016e0be8e8cf98
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1314
Joomla! Component Highslide 1.5 - Local File Inclusion
medium
A directory traversal vulnerability in the Highslide JS (com_hsconfig) component 1.5 and 2.0.9 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1314.yaml
853c0f0e7c9369a9e559f76f451a163485413ed6c6c582c09b4da115e570d951
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1315
Joomla! Component webERPcustomer - Local File Inclusion
medium
A directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1315.yaml
aa4d3c91ed68aa6ea3ca19b2a73df7ef2b15cfa005173f273cc68d2815b77686
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1340
Joomla! Component com_jresearch - 'Controller' Local File Inclusion
medium
A directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1340.yaml
5782b3e158d89278b41331d542f66552ca54d65f21063abb625ae505c3d0e78e
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1345
Joomla! Component Cookex Agency CKForms - Local File Inclusion
medium
A directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1345.yaml
16b66d7306d7a5597f106f7ad7557c64589aad9f1a193c77835f20a3d523fef2
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1352
Joomla! Component Juke Box 1.7 - Local File Inclusion
medium
A directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1352.yaml
71f3e76a30109b4a1cd969e6df672f26cd62af39f139acc66376b3f6fb98ecec
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1353
Joomla! Component LoginBox - Local File Inclusion
medium
A directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.
5.00
http/cves/2010/CVE-2010-1353.yaml
cfca788a031744de322e317a02c68d05ac0a3604c4edbf4b66226a70066143b4
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1354
Joomla! Component VJDEO 1.0 - Local File Inclusion
medium
A directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1354.yaml
6113d78549e561e7988c3487f1affdfa04c8e1be3629b5f5ee8bf1180f74ab69
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1429
Red Hat JBoss Enterprise Application Platform - Sensitive Information Disclosure
medium
Red Hat JBoss Enterprise Application Platform 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 is susceptible to sensitive information disclosure. A remote attacker can obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression.
5.00
http/cves/2010/CVE-2010-1429.yaml
51e9dbc3000c795783db11fabb922daed32b0f0e84e894535b29a065381f7957
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1461
Joomla! Component Photo Battle 1.0.1 - Local File Inclusion
medium
A directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via the view parameter to index.php.
5.00
http/cves/2010/CVE-2010-1461.yaml
6bad8fb424d326118db3dcfbedaba18515af29df5d00f84e43c554bcbdc59b53
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1469
Joomla! Component JProject Manager 1.0 - Local File Inclusion
medium
A directory traversal vulnerability in the Ternaria Informatica JProject Manager (com_jprojectmanager) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
6.80
http/cves/2010/CVE-2010-1469.yaml
ff688d30bd66219434d3f9dbc8b3b82d0fdabc4c471c320445f3ee5a2fb65214
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1470
Joomla! Component Web TV 1.0 - Local File Inclusion
high
A directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read arbitrary files and have possibly other unspecified impacts via a .. (dot dot) in the controller parameter to index.php.
7.50
http/cves/2010/CVE-2010-1470.yaml
9f2414c83a0747918f3d68269c3a94cdfc588b27a672d65adc59ea69b4b42f3b
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1471
Joomla! Component Address Book 1.5.0 - Local File Inclusion
high
A directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
7.50
http/cves/2010/CVE-2010-1471.yaml
987a3629afdba26cf81d97ce7c29a263d79ee3807be60f05b312038e750af388
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1472
Joomla! Component Horoscope 1.5.0 - Local File Inclusion
high
A directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
7.50
http/cves/2010/CVE-2010-1472.yaml
4c9080b67232bd24452fa6b3553a38304dc9318c875093a465f0c7485adfe92d
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1473
Joomla! Component Advertising 0.25 - Local File Inclusion
medium
A directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php.
6.80
http/cves/2010/CVE-2010-1473.yaml
9dabed60ece24940ca6f1bbd4eb43306419f07e467f8c3234cc52b408a019c0f
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1474
Joomla! Component Sweetykeeper 1.5 - Local File Inclusion
medium
A directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php.
6.80
http/cves/2010/CVE-2010-1474.yaml
78ab9674de4f4efa4cbcf39d301706e9f39a0747ac8e5788a9fcd0e8e53b53aa
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1475
Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusion
medium
A directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php.
6.80
http/cves/2010/CVE-2010-1475.yaml
95dfa2dd1b42cbb6cd92fcf414c3393cd7d04b391c0728ae7196876f1fd21141
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1476
Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusion
medium
A directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the view parameter to index.php.
6.80
http/cves/2010/CVE-2010-1476.yaml
89f3c10528edb095e04b24287b05fa6a6b8a5946fb69260c0df074cfbf20698b
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1478
Joomla! Component Jfeedback 1.2 - Local File Inclusion
medium
A directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php.
6.80
http/cves/2010/CVE-2010-1478.yaml
c7f5e8ac5d71beb9e2b39566b81482e59965d734730eb3984eacc34093420120
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1491
Joomla! Component MMS Blog 2.3.0 - Local File Inclusion
medium
A directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1491.yaml
59b79a813bbcf0b5de4050771832b73162c25679ca93d7312ac885506ac3701d
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1494
Joomla! Component AWDwall 1.5.4 - Local File Inclusion
medium
A directory traversal vulnerability in the AWDwall (com_awdwall) component 1.5.4 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1494.yaml
b0b61aab99c1772b29498927718373b26f8d03b2b864f2889b1f2c32085d950e
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1495
Joomla! Component Matamko 1.01 - Local File Inclusion
high
A directory traversal vulnerability in the Matamko (com_matamko) component 1.01 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
7.50
http/cves/2010/CVE-2010-1495.yaml
f387b9c5b72bdcf8b54de7f5ce57b94bd57abc5a23fdf3a6a3fe81a33f9f5135
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1531
Joomla! Component redSHOP 1.0 - Local File Inclusion
high
A directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.
7.50
http/cves/2010/CVE-2010-1531.yaml
379746e647c911c57e8d4a58305349570658a1f5db101e9c1757f84443551edd
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1532
Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusion
medium
A directory traversal vulnerability in the givesight PowerMail Pro (com_powermail) component 1.5.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1532.yaml
45f7608eb002324a2531aa6340dc94d3cf35aea7acd33ebda08d0926f67551ce
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1533
Joomla! Component TweetLA 1.0.1 - Local File Inclusion
high
A directory traversal vulnerability in the TweetLA (com_tweetla) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
7.50
http/cves/2010/CVE-2010-1533.yaml
1b5adf65ae6bf89991d1d1c7290627cb78d9916905ff6a8e015fd74c1c2a2c59
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1534
Joomla! Component Shoutbox Pro - Local File Inclusion
medium
A directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
5.00
http/cves/2010/CVE-2010-1534.yaml
9c8ecf463dd1bcde42116cf05f08980e10abe4db97d2146f256c4939ff3804a5
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00
CVE-2010-1535
Joomla! Component TRAVELbook 1.0.1 - Local File Inclusion
high
A directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php.
7.50
http/cves/2010/CVE-2010-1535.yaml
8241e064a9242c62ede1355366f96e69f1c7a9570426006b537f8f56f3743091
2026-05-29 06:44:59.473821+03:00
2026-05-29 06:44:59.473821+03:00