3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2010-1534
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2010 1 PoC

Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1304
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2010 0 PoCs

Directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-4239
CMS Groupware Web ⚡ nuclei
N/A
UNKNOWN
EPSS
55.8%
2010 1 PoC

Tiki Wiki CMS Groupware 5.2 has Local File Inclusion

CVE-2010-1476
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2010 2 PoCs

Directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the view parameter to index.php.

CVE-2010-1494
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2010 2 PoCs

Directory traversal vulnerability in the AWDwall (com_awdwall) component 1.5.4 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1601
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.8%
2010 2 PoCs

Directory traversal vulnerability in the JA Comment (com_jacomment) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.

CVE-2010-1952
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2010 2 PoCs

Directory traversal vulnerability in the BeeHeard (com_beeheard) and BeeHeard Lite (com_beeheardlite) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1956
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.2%
2010 2 PoCs

Directory traversal vulnerability in the Gadget Factory (com_gadgetfactory) component 1.0.0 and 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

CVE-2010-1980
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.0%
2010 2 PoCs

Directory traversal vulnerability in joomlaflickr.php in the Joomla Flickr (com_joomlaflickr) component 1.0.3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-0982
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.5%
2010 1 PoC

Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1657
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.3%
2010 2 PoCs

Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1603
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.6%
2010 2 PoCs

Directory traversal vulnerability in the ZiMB Core (aka ZiMBCore or com_zimbcore) component 0.1 in the ZiMB Manager collection for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1352
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.0%
2010 2 PoCs

Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

CVE-2010-1302
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.0%
2010 1 PoC

Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

CVE-2010-1305
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.6%
2010 1 PoC

Directory traversal vulnerability in jinventory.php in the JInventory (com_jinventory) component 1.23.02 and possibly other versions before 1.26.03, a module for Joomla!, allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2001-0537
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2001 1 PoC

HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.

CVE-2005-3344
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
10.2%
2005 0 PoCs

The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.

CVE-2005-2428
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
8.6%
2005 2 PoCs

Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.

CVE-2005-4385
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2005 0 PoCs

Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.

CVE-2005-3634
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2005 3 PoCs

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.