Zeros312
CVE-2000-0114 | Microsoft FrontPage Extensions - Information Disclosure | medium | Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. | 5.30 | http/cves/2000/CVE-2000-0114.yaml | 2293076cdb5d79beea73ef1ec05f4e798618f8e606d987c093770ad7bd6338cd | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2000-0760 | Jakarta Tomcat 3.1 and 3.0 - Information Disclosure | medium | Jakarta Tomcat 3.1 and 3.0 under Apache contain a vulnerability in the Snoop servlet that reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension, exploit requires remote access. | 6.40 | http/cves/2000/CVE-2000-0760.yaml | b237c6362ba93981b9ea2dab3b07e626358baad62b871c6a707c28868cd13e00 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2001-0537 | Cisco IOS HTTP Configuration - Authentication Bypass | critical | HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL. | 9.30 | http/cves/2001/CVE-2001-0537.yaml | d6d6e77a5fd43e0f542cd60617d07bf3a039330dcc0d818294483b4a9a93b482 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2002-1131 | SquirrelMail 1.2.6/1.2.7 - Cross-Site Scripting | high | The Virtual Keyboard plugin for SquirrelMail 1.2.6/1.2.7 is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. | 7.50 | http/cves/2002/CVE-2002-1131.yaml | c7e9a484a29636fa8cf2ef229e0ac97627603420274e16fd8f4cae6fc528f750 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2004-0519 | SquirrelMail 1.4.x - Folder Name Cross-Site Scripting | medium | Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php. | 6.80 | http/cves/2004/CVE-2004-0519.yaml | a7823247cf2a4297c741940bbd160a56baba13297f2817412371826c6058c6f6 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2004-1965 | Open Bulletin Board (OpenBB) v1.0.6 - Open Redirect/XSS | medium | Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) redirect parameter to member.php, (2) to parameter to myhome.php (3) TID parameter to post.php, or (4) redirect parameter to index.php. | 4.30 | http/cves/2004/CVE-2004-1965.yaml | 406fc03c9c94ed7972a535e956c23f5ea02ed6eb67aaa7186c7d09607e43cb2b | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2005-2428 | Lotus Domino R5 and R6 WebMail - Information Disclosure | medium | Lotus Domino R5 and R6 WebMail with 'Generate HTML for all fields' enabled (which is by default) allows remote attackers to read the HTML source to obtain sensitive information including the password hash in the HTTPPassword field, the password change date in the HTTPPasswordChangeDate field, and the client Lotus Domino release in the ClntBld field (a different vulnerability than CVE-2005-2696). | 5.00 | http/cves/2005/CVE-2005-2428.yaml | a0f5f769d10adefb84b29d636c6de51da9e4f0dec3511b0d905bc529e5a98d43 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2005-3128 | SquirrelMail Address Add 1.4.2 - Cross-Site Scripting | medium | SquirrelMail Address Add 1.4.2 plugin contains a cross-site scripting vulnerability. It fails to properly sanitize user-supplied input, thus allowing an attacker to execute arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. | 5.40 | http/cves/2005/CVE-2005-3128.yaml | 1c623ee9be0651d23b03632d9c0115a82b1a48274c04d3c67af17b6a772571c8 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2005-3344 | Horde Groupware Unauthenticated Admin Access | critical | Horde Groupware contains an administrative account with a blank password, which allows remote attackers to gain access. | 10.00 | http/cves/2005/CVE-2005-3344.yaml | e92b596852cda38a2a738732fc41caaffc77281224e8daf6378f28b8316a27c5 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2005-3634 | SAP Web Application Server 6.x/7.0 - Open Redirect | medium | frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter. | 5.00 | http/cves/2005/CVE-2005-3634.yaml | f7aa4e41d4c0c315e8710858b205f8704f653d10f73dce55d139c07f9b9eafa7 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2005-4385 | Cofax <=2.0RC3 - Cross-Site Scripting | medium | Cofax 2.0 RC3 and earlier contains a cross-site scripting vulnerability in search.htm which allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter. | 4.30 | http/cves/2005/CVE-2005-4385.yaml | ea383b693c7e8e23d9fdd534dc92d951a03b5d6ea0741b7f798f029c8e2ddda8 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2006-1681 | Cherokee HTTPD <=0.5 - Cross-Site Scripting | medium | Cherokee HTTPD 0.5 and earlier contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated. | 4.30 | http/cves/2006/CVE-2006-1681.yaml | 13e0bcec8dbfae70e2d8c9937d25aaf8358c8b10d10e79ca6eb56e11629ecbc7 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2006-2842 | Squirrelmail <=1.4.6 - Local File Inclusion | high | SquirrelMail 1.4.6 and earlier versions are susceptible to a PHP local file inclusion vulnerability in functions/plugin.php if register_globals is enabled and magic_quotes_gpc is disabled. This allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter. | 7.50 | http/cves/2006/CVE-2006-2842.yaml | 4a74e1ea4fc517cc67870de30242689e97081a7eed2cfc90974be29f71dac8c8 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2006-3392 | Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure | medium | Webmin before 1.290 and Usermin before 1.220 contain a path traversal caused by calling the simplify_path function before decoding HTML, letting remote attackers read arbitrary files, exploit requires sending crafted '..%01' sequences. | 5.00 | http/cves/2006/CVE-2006-3392.yaml | 47fda3ba4f0b726191af20170292b2ca65862afe66a02da8b04714f88a00694f | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2007-0885 | Jira Rainbow.Zen - Cross-Site Scripting | medium | Jira Rainbow.Zen contains a cross-site scripting vulnerability via Jira/secure/BrowseProject.jspa which allows remote attackers to inject arbitrary web script or HTML via the id parameter. | 6.80 | http/cves/2007/CVE-2007-0885.yaml | da3e3ee590137c4d1390c1e0ce35ab326f76e336ec37340b0009b07c5e895dd6 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2007-2449 | Apache Tomcat 4.x-7.x - Cross-Site Scripting | medium | Apache Tomcat 4.x through 7.x contains a cross-site scripting vulnerability which an attacker can use to execute arbitrary script in the browser of an unsuspecting user in the context of the affected site. | 7.20 | http/cves/2007/CVE-2007-2449.yaml | a7f0a272dec58e4d33cc218437a70bfea0b2d7ff490968ff56ce6eb3409e27cd | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2007-3010 | Alcatel-Lucent OmniPCX - Remote Command Execution | critical | The OmniPCX web interface has a script "masterCGI" with a remote command execution vulnerability via the "user" parameter. | 10.00 | http/cves/2007/CVE-2007-3010.yaml | 0492b759a8d8284045ba0988608e5146f77fa9ac7c6ba8df67ffd7be71be5cb0 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2007-4504 | Joomla! RSfiles <=1.0.2 - Local File Inclusion | medium | Joomla! RSfiles 1.0.2 and earlier is susceptible to local file inclusion in index.php in the RSfiles component (com_rsfiles). This could allow remote attackers to arbitrarily read files via a .. (dot dot) in the path parameter in a files.display action. | 5.00 | http/cves/2007/CVE-2007-4504.yaml | 4bd958b9974ea07c424e82cdf02b64a4c4481aa0c0e890d62e28c5f5832d0bd8 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2007-4556 | OpenSymphony XWork/Apache Struts2 - Remote Code Execution | medium | Apache Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via for"m input beginning with a "%{" sequence and ending with a "}" character. | 6.80 | http/cves/2007/CVE-2007-4556.yaml | 78e7607b57054674f5538bf4cc8be207f5627ff2fa2dde2c49778c7b2c8b66cf | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2007-5728 | phpPgAdmin <=4.1.1 - Cross-Site Scripting | medium | phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, is vulnerable to cross-site scripting and allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php, which are different vectors than CVE-2007-2865. | 4.30 | http/cves/2007/CVE-2007-5728.yaml | 1b8cd2ba3249d81e279683bf0c0ff06f3a5b5fc25d4aafd9063e4a9e56dcb300 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-1059 | WordPress Sniplets 1.1.2 - Local File Inclusion | high | PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter. | 7.50 | http/cves/2008/CVE-2008-1059.yaml | a43e83ef89ba87c7f1115153b0657b5ec34562870762b3e69790b2e88a110435 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-1061 | WordPress Sniplets <=1.2.2 - Cross-Site Scripting | medium | WordPress Sniplets 1.1.2 and 1.2.2 plugin contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary web script or HTML via the text parameter to warning.php, notice.php, and inset.php in view/sniplets/, and possibly modules/execute.php; via the url parameter to view/admin/submenu.php; and via the page parameter to view/admin/pager.php. | 4.30 | http/cves/2008/CVE-2008-1061.yaml | 6439729ff89e5e03982cbd25b971615a3ce996b2848ee35a436b1cdab24b724b | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-1547 | Microsoft OWA Exchange Server 2003 - 'redir.asp' Open Redirection | medium | Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter. | 4.30 | http/cves/2008/CVE-2008-1547.yaml | d6937f15c324eceb6597653d2c17b074308f1253c54be264b22c8b7b856e5f7e | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-2398 | AppServ Open Project <=2.5.10 - Cross-Site Scripting | medium | AppServ Open Project 2.5.10 and earlier contains a cross-site scripting vulnerability in index.php which allows remote attackers to inject arbitrary web script or HTML via the appservlang parameter. | 4.30 | http/cves/2008/CVE-2008-2398.yaml | c8bbf71e1084cc6c6ee0fd59b243f538a041261371d73de9cd35770eced50bf5 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-2650 | CMSimple 3.1 - Local File Inclusion | medium | CMSimple 3.1 is susceptible to local file inclusion via cmsimple/cms.php when register_globals is enabled which allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sl parameter to index.php. NOTE: this can be leveraged for remote file execution by including adm.php and then invoking the upload action. NOTE: on 20080601, the vendor patched 3.1 without changing the version number. | 6.80 | http/cves/2008/CVE-2008-2650.yaml | 1f27767429188582514b05d7f401426470c69240ccc44ebadc1fad592680e1fc | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-4668 | Joomla! Image Browser 0.1.5 rc2 - Local File Inclusion | critical | Joomla! Image Browser 0.1.5 rc2 is susceptible to local file inclusion via com_imagebrowser which could allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder parameter to index.php. | 9.00 | http/cves/2008/CVE-2008-4668.yaml | e8975d9205fded101a2412ca0c21a375772fb1a097fd8191ced51a1511ca4d2c | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-4764 | Joomla! <=2.0.0 RC2 - Local File Inclusion | medium | Joomla! 2.0.0 RC2 and earlier are susceptible to local file inclusion in the eXtplorer module (com_extplorer) that allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action. | 5.00 | http/cves/2008/CVE-2008-4764.yaml | e2512300505218d1a6f01ef954057af020955b77d807548cc9aa7c09938d86da | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-5587 | phpPgAdmin <=4.2.1 - Local File Inclusion | medium | phpPgAdmin 4.2.1 is vulnerable to local file inclusion in libraries/lib.inc.php when register globals is enabled. Remote attackers can read arbitrary files via a .. (dot dot) in the _language parameter to index.php. | 4.30 | http/cves/2008/CVE-2008-5587.yaml | 5f46be67cebf29835395b517d3a160d58628c8012f6bca12f29a633c5c0a5579 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-6080 | Joomla! ionFiles 4.4.2 - Local File Inclusion | medium | Joomla! ionFiles 4.4.2 is susceptible to local file inclusion in download.php in the ionFiles (com_ionfiles) that allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | 5.00 | http/cves/2008/CVE-2008-6080.yaml | b5adb0b863f70291492e8dbbdf9d4f83990b2bfe3bd28031b117b7ae219eec99 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-6172 | Joomla! Component RWCards 3.0.11 - Local File Inclusion | medium | A directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla! when magic_quotes_gpc is disabled allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the img parameter. | 6.80 | http/cves/2008/CVE-2008-6172.yaml | a5b7217614cecabfe8f0e99a971f1cfd860ef109dae208ffb6debf593d5c53a1 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-6222 | Joomla! ProDesk 1.0/1.2 - Local File Inclusion | medium | Joomla! Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter to index.php. | 5.00 | http/cves/2008/CVE-2008-6222.yaml | 77ecd943908c957ffac1aefd0f1f476fa8f6bf30c9278ed756282919b9804a06 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-6465 | Parallels H-Sphere 3.0.0 P9/3.1 P1 - Cross-Site Scripting | medium | Parallels H-Sphere 3.0.0 P9 and 3.1 P1 contains multiple cross-site scripting vulnerabilities in login.php in webshell4. An attacker can inject arbitrary web script or HTML via the err, errorcode, and login parameters, thus allowing theft of cookie-based authentication credentials and launch of other attacks. | 4.30 | http/cves/2008/CVE-2008-6465.yaml | 4517a7692d9d1ad6bd9f21073b9a287983c181076b814fb362791564dd5879b8 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-6668 | nweb2fax <=0.2.7 - Local File Inclusion | medium | nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via the id parameter submitted to comm.php and the var_filename parameter submitted to viewrq.php. | 5.00 | http/cves/2008/CVE-2008-6668.yaml | 4306c5ec0f5d9435c2aab116a5be74f2478ecb2b90427f80a07c96b312058d11 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-6982 | Devalcms 1.4a - Cross-Site Scripting | medium | Devalcms 1.4a contains a cross-site scripting vulnerability in the currentpath parameter of the index.php file. | 4.30 | http/cves/2008/CVE-2008-6982.yaml | d708da967c3a8e63f94d4aafaa10b083f18a9649f8e8ff9ccb58c31efd8ae844 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2008-7269 | UC Gateway Investment SiteEngine v5.0 - Open Redirect | medium | Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the forward parameter in a logout action. | 5.80 | http/cves/2008/CVE-2008-7269.yaml | 0b26d98e4378f67c5e363e0bdd586499b6814d05b13a732167de4ec8d2d5d89a | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-0347 | Autonomy Ultraseek - Open Redirect | medium | Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter. | 5.80 | http/cves/2009/CVE-2009-0347.yaml | 4a189d4fe568bda15175e069b9fcb9384e3c5c1395eaa19950389986e9720b48 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-0545 | ZeroShell <= 1.0beta11 Remote Code Execution | critical | ZeroShell 1.0beta11 and earlier via cgi-bin/kerbynet allows remote attackers to execute arbitrary commands through shell metacharacters in the type parameter in a NoAuthREQ x509List action. | 10.00 | http/cves/2009/CVE-2009-0545.yaml | 983d2c59a29df18655bd5cccb3a53085b7682bd41d482a2d1182bcd7e7da7ea3 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-0932 | Horde/Horde Groupware - Local File Inclusion | medium | Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 are susceptible to local file inclusion in framework/Image/Image.php because it allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name. | 6.40 | http/cves/2009/CVE-2009-0932.yaml | 1c42053411b559b3a9f7238af9f43dcf0da058672f988030432727c42ef92516 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-1151 | PhpMyAdmin Scripts - Remote Code Execution | high | PhpMyAdmin Scripts 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 are susceptible to a remote code execution in setup.php that allows remote attackers to inject arbitrary PHP code into a configuration file via the save action. Combined with the ability to save files on server, this can allow unauthenticated users to execute arbitrary PHP code. | 7.50 | http/cves/2009/CVE-2009-1151.yaml | 4b9f1475dcd71ca42a137a026a996635843082e5a179d58993b2f44ccee642ca | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-1496 | Joomla! Cmimarketplace 0.1 - Local File Inclusion | medium | Joomla! Cmimarketplace 0.1 is susceptible to local file inclusion because com_cmimarketplace allows remote attackers to list arbitrary directories via a .. (dot dot) in the viewit parameter to index.php. | 5.00 | http/cves/2009/CVE-2009-1496.yaml | 6f2ef307565e94c563adead4d9c5bf4aaa88e0d384ab05552909fc1f4265dd48 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-1558 | Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusion | high | Cisco Linksys WVC54GCA 1.00R22/1.00R24 is susceptible to local file inclusion in adm/file.cgi because it allows remote attackers to read arbitrary files via a %2e. (encoded dot dot) or an absolute pathname in the next_file parameter. | 7.80 | http/cves/2009/CVE-2009-1558.yaml | a971d5fa344633084c1a4c07e43559a26ec11bce7ddb0475f4c4de00c222b607 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-1872 | Adobe Coldfusion <=8.0.1 - Cross-Site Scripting | medium | Adobe ColdFusion Server 8.0.1 and earlier contain multiple cross-site scripting vulnerabilities which allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm. | 4.30 | http/cves/2009/CVE-2009-1872.yaml | 47ef1374245b69e438ddb6f64e18c1554f16efd2dab45a93d234a616a1dff4d5 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-2015 | Joomla! MooFAQ 1.0 - Local File Inclusion | high | Joomla! Ideal MooFAQ 1.0 via com_moofaq allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter (local file inclusion). | 7.50 | http/cves/2009/CVE-2009-2015.yaml | 7109a472867694cd877fb1b2576a609ad227c051e51d211d86487a4f0dd27024 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-2100 | Joomla! JoomlaPraise Projectfork 2.0.10 - Local File Inclusion | medium | Joomla! JoomlaPraise Projectfork (com_projectfork) 2.0.10 allows remote attackers to read arbitrary files via local file inclusion in the section parameter to index.php. | 5.00 | http/cves/2009/CVE-2009-2100.yaml | 66c2404e98c87752e02d07b3114f7715ae6db1133fdc37c8404dc1d6755d502f | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-3053 | Joomla! Agora 3.0.0b - Local File Inclusion | medium | Joomla! Agora 3.0.0b (com_agora) allows remote attackers to include and execute arbitrary local files via local file inclusion in the action parameter to the avatars page, reachable through index.php. | 6.80 | http/cves/2009/CVE-2009-3053.yaml | c5e4bdeeb39ff9faa7959fbd940531394eb6dbeb77819f1a34d8f160515d3f2c | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-3318 | Joomla! Roland Breedveld Album 1.14 - Local File Inclusion | high | Joomla! Roland Breedveld Album 1.14 (com_album) is susceptible to local file inclusion because it allows remote attackers to access arbitrary directories and have unspecified other impact via a .. (dot dot) in the target parameter to index.php. | 7.50 | http/cves/2009/CVE-2009-3318.yaml | 1cec3bdc07e98c8c4795bad5c784ff8064178ca7c478c99ceeedfa1a8f50c18e | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-4202 | Joomla! Omilen Photo Gallery 0.5b - Local File Inclusion | high | Joomla! Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php. | 7.50 | http/cves/2009/CVE-2009-4202.yaml | 4c8b63bf5d9540e7b5d98b72bb099718aa72563b6ec59a6dc8d00e4a18b1d257 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-4223 | KR-Web <=1.1b2 - Remote File Inclusion | high | KR-Web 1.1b2 and prior contain a remote file inclusion vulnerability via adm/krgourl.php, which allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. | 7.50 | http/cves/2009/CVE-2009-4223.yaml | 55dd10b9059acf12beff710233d280eedc6782fa9a171b1395de9bf60112ef87 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-4679 | Joomla! Portfolio Nexus - Remote File Inclusion | high | Joomla! Portfolio Nexus 1.5 contains a remote file inclusion vulnerability in the inertialFATE iF (com_if_nexus) component that allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. | 7.50 | http/cves/2009/CVE-2009-4679.yaml | 32693928142aa26fae3418e99a04e651fc49e37c1befb45d5021646dd083a9d6 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-5020 | AWStats < 6.95 - Open Redirect | medium | An open redirect vulnerability in awredir.pl in AWStats < 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | 5.80 | http/cves/2009/CVE-2009-5020.yaml | d5692428795c9a6992da36131182b3285514f3fb2875211a7bd3134121966e66 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2009-5114 | WebGlimpse 2.18.7 - Directory Traversal | medium | A directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the DOC parameter. | 5.00 | http/cves/2009/CVE-2009-5114.yaml | 798560daf2c4b6a573de489512424e88ef6429645c7bb14c8f9dcad80a170000 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-0157 | Joomla! Component com_biblestudy - Local File Inclusion | high | A directory traversal vulnerability in the Bible Study (com_biblestudy) component 6.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter in a studieslist action to index.php. | 7.50 | http/cves/2010/CVE-2010-0157.yaml | 085f3e347367b090fb6b11fbafd2937c9e12c8327f9091e3d09c890882d6895d | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-0219 | Apache Axis2 Default Login | critical | Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service. | 10.00 | http/cves/2010/CVE-2010-0219.yaml | 5ee462e71f708590ef100b27509172c7da1e8f4444985c880d1d3373322761d2 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-0467 | Joomla! Component CCNewsLetter - Local File Inclusion | medium | A directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php. | 5.80 | http/cves/2010/CVE-2010-0467.yaml | 661bf98ff81ff9b07eb52709a7a07d8c32e7ef99715ba39c13155d27b48da6eb | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-0696 | Joomla! Component Jw_allVideos - Arbitrary File Retrieval | medium | A directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../.../ (modified dot dot) in the file parameter. | 5.00 | http/cves/2010/CVE-2010-0696.yaml | fe463a71b9d2e71857a0c7fb488e6c29d7abcb1dc263bd2c19e6cf7d3dd0da25 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-0759 | Joomla! Plugin Core Design Scriptegrator - Local File Inclusion | high | A directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allows remote attackers to read, and possibly include and execute, arbitrary files via directory traversal sequences in the files[] parameter. | 7.50 | http/cves/2010/CVE-2010-0759.yaml | a175d3830aec4d35425010fadd0324f4298e8cad56d9c2d5d8cc239cce3ebe43 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-0942 | Joomla! Component com_jvideodirect - Directory Traversal | medium | Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-0942.yaml | de5bd8b83209e28c0dbfd7ce5a3de27f8acf0a700720e4f90b6a6ed3137a897b | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-0943 | Joomla! Component com_jashowcase - Directory Traversal | medium | A directory traversal vulnerability in the JA Showcase (com_jashowcase) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a jashowcase action to index.php. | 5.00 | http/cves/2010/CVE-2010-0943.yaml | e4c0f9bdec4e751eea98b0d90515dc2b0c682626f823613e60bbaa00ed561656 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-0944 | Joomla! Component com_jcollection - Directory Traversal | medium | A directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-0944.yaml | 1e66e3d13ada191ad9408e1663090a6b64ec74214e7061eaa8dfda018938527c | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-0972 | Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusion | high | A directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. | 7.50 | http/cves/2010/CVE-2010-0972.yaml | 00d9a05b613e32024cfb22f93dc2a2657d1fb733f70d65e3d9bb06ff5b822561 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-0982 | Joomla! Component com_cartweberp - Local File Inclusion | medium | A directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 4.30 | http/cves/2010/CVE-2010-0982.yaml | 21b0f1ba045cec5b4ecbe82a6b9fdce698aeb0857f0be5275b44deaad872642d | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-0985 | Joomla! Component com_abbrev - Local File Inclusion | high | A directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. | 7.50 | http/cves/2010/CVE-2010-0985.yaml | d6721fff7ebc9367548de39d0cb50daaa56c6cc5110aa277df32706b011ccb94 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1056 | Joomla! Component com_rokdownloads - Local File Inclusion | medium | A directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. | 6.80 | http/cves/2010/CVE-2010-1056.yaml | fb3933158fab82209a3b9f442895a2db1e0d88b4dbe79ddd4ec9fad687e6a815 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1081 | Joomla! Component com_communitypolls 1.5.2 - Local File Inclusion | medium | A directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1081.yaml | f04dd231624b2ed494686e06e9ac0a05f615f58651cec4d1a5ba736091e72fbc | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1217 | Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusion | medium | A directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE -- the original researcher states that the affected product is JE Tooltip, not Form Creator; however, the exploit URL suggests that Form Creator is affected. | 4.30 | http/cves/2010/CVE-2010-1217.yaml | 433b458c283a2bf1172ff96290d99b3c4f7384751215a6dc490a2148f4ef3f38 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1219 | Joomla! Component com_janews - Local File Inclusion | medium | A directory traversal vulnerability in the JA News (com_janews) component 1.0 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. | 6.80 | http/cves/2010/CVE-2010-1219.yaml | dd4955735b5d7b09bca00f52358838cd27de368ae79315d8379d7b56f339b383 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1302 | Joomla! Component DW Graph - Local File Inclusion | medium | A directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1302.yaml | 31189db05762488e03488ba29ded4226da03064934445affdcc9e5029e558fab | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1304 | Joomla! Component User Status - Local File Inclusion | medium | A directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1304.yaml | 3955704d5242ef8fb09f2d9d8512b59c8974fc09b1a6b3474ee367ede0f18326 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1305 | Joomla! Component JInventory 1.23.02 - Local File Inclusion | medium | A directory traversal vulnerability in jinventory.php in the JInventory (com_jinventory) component 1.23.02 and possibly other versions before 1.26.03, a module for Joomla!, allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1305.yaml | 77886331b647fe5989ec2f6315e06a55679dee32395c02d0af4b416bc91a7c8d | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1306 | Joomla! Component Picasa 2.0 - Local File Inclusion | high | A directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. | 7.50 | http/cves/2010/CVE-2010-1306.yaml | 9b0aed347c555c607d111a137fb72a43803e202bdf66af1d239f554ed37c5255 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1307 | Joomla! Component Magic Updater - Local File Inclusion | medium | A directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1307.yaml | 0aceeac56b52eb2e2ee2cde8771c6e4c3d14e8bc02a8d1ab11c2db9e0f9ada2a | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1308 | Joomla! Component SVMap 1.1.1 - Local File Inclusion | medium | A directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1308.yaml | 180dda0721980f170c374805293850f3df83419b3e4e578eddef7e44285da044 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1312 | Joomla! Component News Portal 1.5.x - Local File Inclusion | medium | A directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1312.yaml | 654942c363cd9f9e46ee1da438aa9ff426e1f171ebf851cdd7b15ae2c09b3a98 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1313 | Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusion | medium | A directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0.12 and 1.0.0.13 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. | 4.30 | http/cves/2010/CVE-2010-1313.yaml | d7033c23d9e55249c5a0b48ad9cab1e3240150e1cf172bc997016e0be8e8cf98 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1314 | Joomla! Component Highslide 1.5 - Local File Inclusion | medium | A directory traversal vulnerability in the Highslide JS (com_hsconfig) component 1.5 and 2.0.9 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1314.yaml | 853c0f0e7c9369a9e559f76f451a163485413ed6c6c582c09b4da115e570d951 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1315 | Joomla! Component webERPcustomer - Local File Inclusion | medium | A directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1315.yaml | aa4d3c91ed68aa6ea3ca19b2a73df7ef2b15cfa005173f273cc68d2815b77686 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1340 | Joomla! Component com_jresearch - 'Controller' Local File Inclusion | medium | A directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1340.yaml | 5782b3e158d89278b41331d542f66552ca54d65f21063abb625ae505c3d0e78e | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1345 | Joomla! Component Cookex Agency CKForms - Local File Inclusion | medium | A directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1345.yaml | 16b66d7306d7a5597f106f7ad7557c64589aad9f1a193c77835f20a3d523fef2 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1352 | Joomla! Component Juke Box 1.7 - Local File Inclusion | medium | A directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1352.yaml | 71f3e76a30109b4a1cd969e6df672f26cd62af39f139acc66376b3f6fb98ecec | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1353 | Joomla! Component LoginBox - Local File Inclusion | medium | A directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1353.yaml | cfca788a031744de322e317a02c68d05ac0a3604c4edbf4b66226a70066143b4 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1354 | Joomla! Component VJDEO 1.0 - Local File Inclusion | medium | A directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1354.yaml | 6113d78549e561e7988c3487f1affdfa04c8e1be3629b5f5ee8bf1180f74ab69 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1429 | Red Hat JBoss Enterprise Application Platform - Sensitive Information Disclosure | medium | Red Hat JBoss Enterprise Application Platform 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 is susceptible to sensitive information disclosure. A remote attacker can obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression. | 5.00 | http/cves/2010/CVE-2010-1429.yaml | 51e9dbc3000c795783db11fabb922daed32b0f0e84e894535b29a065381f7957 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1461 | Joomla! Component Photo Battle 1.0.1 - Local File Inclusion | medium | A directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via the view parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1461.yaml | 6bad8fb424d326118db3dcfbedaba18515af29df5d00f84e43c554bcbdc59b53 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1469 | Joomla! Component JProject Manager 1.0 - Local File Inclusion | medium | A directory traversal vulnerability in the Ternaria Informatica JProject Manager (com_jprojectmanager) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | 6.80 | http/cves/2010/CVE-2010-1469.yaml | ff688d30bd66219434d3f9dbc8b3b82d0fdabc4c471c320445f3ee5a2fb65214 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1470 | Joomla! Component Web TV 1.0 - Local File Inclusion | high | A directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read arbitrary files and have possibly other unspecified impacts via a .. (dot dot) in the controller parameter to index.php. | 7.50 | http/cves/2010/CVE-2010-1470.yaml | 9f2414c83a0747918f3d68269c3a94cdfc588b27a672d65adc59ea69b4b42f3b | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1471 | Joomla! Component Address Book 1.5.0 - Local File Inclusion | high | A directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 7.50 | http/cves/2010/CVE-2010-1471.yaml | 987a3629afdba26cf81d97ce7c29a263d79ee3807be60f05b312038e750af388 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1472 | Joomla! Component Horoscope 1.5.0 - Local File Inclusion | high | A directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 7.50 | http/cves/2010/CVE-2010-1472.yaml | 4c9080b67232bd24452fa6b3553a38304dc9318c875093a465f0c7485adfe92d | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1473 | Joomla! Component Advertising 0.25 - Local File Inclusion | medium | A directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. | 6.80 | http/cves/2010/CVE-2010-1473.yaml | 9dabed60ece24940ca6f1bbd4eb43306419f07e467f8c3234cc52b408a019c0f | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1474 | Joomla! Component Sweetykeeper 1.5 - Local File Inclusion | medium | A directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. | 6.80 | http/cves/2010/CVE-2010-1474.yaml | 78ab9674de4f4efa4cbcf39d301706e9f39a0747ac8e5788a9fcd0e8e53b53aa | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1475 | Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusion | medium | A directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. | 6.80 | http/cves/2010/CVE-2010-1475.yaml | 95dfa2dd1b42cbb6cd92fcf414c3393cd7d04b391c0728ae7196876f1fd21141 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1476 | Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusion | medium | A directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the view parameter to index.php. | 6.80 | http/cves/2010/CVE-2010-1476.yaml | 89f3c10528edb095e04b24287b05fa6a6b8a5946fb69260c0df074cfbf20698b | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1478 | Joomla! Component Jfeedback 1.2 - Local File Inclusion | medium | A directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. | 6.80 | http/cves/2010/CVE-2010-1478.yaml | c7f5e8ac5d71beb9e2b39566b81482e59965d734730eb3984eacc34093420120 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1491 | Joomla! Component MMS Blog 2.3.0 - Local File Inclusion | medium | A directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1491.yaml | 59b79a813bbcf0b5de4050771832b73162c25679ca93d7312ac885506ac3701d | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1494 | Joomla! Component AWDwall 1.5.4 - Local File Inclusion | medium | A directory traversal vulnerability in the AWDwall (com_awdwall) component 1.5.4 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1494.yaml | b0b61aab99c1772b29498927718373b26f8d03b2b864f2889b1f2c32085d950e | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1495 | Joomla! Component Matamko 1.01 - Local File Inclusion | high | A directory traversal vulnerability in the Matamko (com_matamko) component 1.01 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 7.50 | http/cves/2010/CVE-2010-1495.yaml | f387b9c5b72bdcf8b54de7f5ce57b94bd57abc5a23fdf3a6a3fe81a33f9f5135 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1531 | Joomla! Component redSHOP 1.0 - Local File Inclusion | high | A directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. | 7.50 | http/cves/2010/CVE-2010-1531.yaml | 379746e647c911c57e8d4a58305349570658a1f5db101e9c1757f84443551edd | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1532 | Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusion | medium | A directory traversal vulnerability in the givesight PowerMail Pro (com_powermail) component 1.5.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1532.yaml | 45f7608eb002324a2531aa6340dc94d3cf35aea7acd33ebda08d0926f67551ce | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1533 | Joomla! Component TweetLA 1.0.1 - Local File Inclusion | high | A directory traversal vulnerability in the TweetLA (com_tweetla) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 7.50 | http/cves/2010/CVE-2010-1533.yaml | 1b5adf65ae6bf89991d1d1c7290627cb78d9916905ff6a8e015fd74c1c2a2c59 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1534 | Joomla! Component Shoutbox Pro - Local File Inclusion | medium | A directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | 5.00 | http/cves/2010/CVE-2010-1534.yaml | 9c8ecf463dd1bcde42116cf05f08980e10abe4db97d2146f256c4939ff3804a5 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |
CVE-2010-1535 | Joomla! Component TRAVELbook 1.0.1 - Local File Inclusion | high | A directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. | 7.50 | http/cves/2010/CVE-2010-1535.yaml | 8241e064a9242c62ede1355366f96e69f1c7a9570426006b537f8f56f3743091 | 2026-05-29 06:44:59.473821+03:00 | 2026-05-29 06:44:59.473821+03:00 |