CVE Database - 2011

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

1458
Matching CVEs
16133
Critical
35026
High
84348
High WAF Coverage

CVE-2011-4251

HIGH
9.30 CVSS 2.0

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted sample size in a RealAudio file.

Code Injection
WAF: Medium

CVE-2011-4249

HIGH
10.00 CVSS 2.0

Array index error in the RV30 codec in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via unspecified vectors.

Improper Input Validation
WAF: Medium

CVE-2011-4248

HIGH
9.30 CVSS 2.0

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a malformed AAC file.

Code Injection
WAF: Medium

CVE-2011-4247

HIGH
9.30 CVSS 2.0

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted QCELP stream.

Code Injection
WAF: Medium

CVE-2011-4312

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in the commenting system in Review Board before 1.5.7 and 1.6.x before 1.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) diff viewer or (2) screenshot component.

Cross-Site Scripting (XSS)
WAF: High

CVE-2011-4332

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.6.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2010-5062

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in search.php in MH Products kleinanzeigenmarkt allows remote attackers to execute arbitrary SQL commands via the c parameter.

SQL Injection
WAF: High

CVE-2010-5061

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in index.php in RSStatic allows remote attackers to execute arbitrary SQL commands via the maxarticles parameter.

SQL Injection
WAF: High

CVE-2010-5060

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.

SQL Injection
WAF: High

CVE-2010-5059

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in index.php in CMScout 2.0.8 allows remote attackers to execute arbitrary SQL commands via the album parameter in a photos action.

SQL Injection
WAF: High

CVE-2010-5058

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the res_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

SQL Injection
WAF: High

CVE-2010-5057

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the tipodoc_id parameter.

SQL Injection
WAF: High

CVE-2010-5056

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the face_id parameter in a show_face action to index.php.

SQL Injection
WAF: High

CVE-2010-5055

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in index.php in Almnzm 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

SQL Injection
WAF: High

CVE-2010-5054

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Special:Login in JAMWiki before 0.8.4 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2010-5053

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in the XOBBIX (com_xobbix) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a prod_desc action to index.php.

SQL Injection
WAF: High

CVE-2010-5052

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in admin/components.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the val[] parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2010-5051

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in admin/core/admin_func.php in razorCMS 1.0 stable allows remote attackers to inject arbitrary web script or HTML via the content parameter in an edit action to admin/index.php.

Cross-Site Scripting (XSS)
WAF: High

CVE-2010-5050

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in jsp/admin/tools/remote_share.jsp in ManageEngine ADManager Plus 4.4.0 allows remote attackers to inject arbitrary web script or HTML via the computerName parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Cross-Site Scripting (XSS)
WAF: High

CVE-2010-5049

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in events.php in Zabbix 1.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the nav_time parameter.

SQL Injection
WAF: High

CVE-2010-5048

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inject arbitrary web script or HTML via the name parameter to index.php.

Cross-Site Scripting (XSS)
WAF: High

CVE-2010-5047

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

SQL Injection
WAF: High

CVE-2010-5046

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in admin.php in ecoCMS allows remote attackers to inject arbitrary web script or HTML via the p parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2011-4502

HIGH
10.00 CVSS 2.0

The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.

OS Command Injection
WAF: High

CVE-2011-4498

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in the web console in Zenprise Device Manager 6.x through 6.1.8 allows remote attackers to hijack the authentication of administrators for requests that wipe mobile devices.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2011-4465

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in IBM Lotus Mobile Connect (LMC) 6.1.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden redirect URL.

Cross-Site Scripting (XSS)
WAF: High

CVE-2011-4311

MEDIUM
5.00 CVSS 2.0

ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unspecified vectors.

Improper Input Validation
WAF: Medium

CVE-2011-4122

MEDIUM
6.90 CVSS 2.0

Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to kcheckpass.

Path Traversal
WAF: High

CVE-2011-4107

MEDIUM
6.50 CVSS 3.1

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

XML External Entity (XXE)
WAF: High

CVE-2011-3646

MEDIUM
5.00 CVSS 2.0

phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to phpmyadmin.css.php, which reveals the installation path in an error message.

Improper Input Validation
WAF: Medium

CVE-2011-2770

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in man2html.cgi.c in man2html 1.6, and possibly other version, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to error messages.

Cross-Site Scripting (XSS)
WAF: High

CVE-2011-4156

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0x and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4155.

Cross-Site Scripting (XSS)
WAF: High

CVE-2011-4155

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0x and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4156.

Cross-Site Scripting (XSS)
WAF: High

CVE-2011-2773

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in Mahara before 1.4.1 allows remote attackers to hijack the authentication of administrators for requests that add a user to an institution.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2011-2772

MEDIUM
5.00 CVSS 2.0

The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote attackers to cause a denial of service (memory consumption) via a (1) large or (2) invalid image.

Improper Input Validation
WAF: Medium

CVE-2011-2771

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in Mahara before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) URI attributes and (2) the External Feed component, as demonstrated by the guid element in an RSS feed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2011-4436

LOW
3.50 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface on the Dell KACE K2000 System Deployment Appliance allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2011-4047

HIGH
9.30 CVSS 2.0

The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access.

Code Injection
WAF: Medium

CVE-2011-3898

HIGH
7.50 CVSS 2.0

Google Chrome before 15.0.874.120, when Java Runtime Environment (JRE) 7 is used, does not request user confirmation before applet execution begins, which allows remote attackers to have an unspecified impact via a crafted applet.

Improper Privilege Management
WAF: Low

CVE-2011-4431

MEDIUM
6.50 CVSS 2.0

Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a .. (dot dot) in the command_name parameter.

Path Traversal
WAF: High

CVE-2011-3985

LOW
2.60 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Plume before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2011-3999

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the RSS/Atom feed-reader implementation in Iwate Portal Bar allows remote attackers to inject arbitrary web script or HTML via a crafted feed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2011-3998

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Apple WebObjects 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2011-3997

HIGH
7.50 CVSS 2.0

Opengear console servers with firmware before 2.2.1 allow remote attackers to bypass authentication, and modify settings or access connected equipment, via unspecified vectors.

Improper Authentication
WAF: Low

CVE-2011-3655

HIGH
9.30 CVSS 2.0

Mozilla Firefox 4.x through 7.0 and Thunderbird 5.0 through 7.0 perform access control without checking for use of the NoWaiverWrapper wrapper, which allows remote attackers to gain privileges via a crafted web site.

Code Injection
WAF: Medium

CVE-2011-3648

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 allows remote attackers to inject arbitrary web script or HTML via crafted text with Shift JIS encoding.

Cross-Site Scripting (XSS)
WAF: High

CVE-2011-3647

HIGH
9.30 CVSS 2.0

The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.

Improper Input Validation
WAF: Medium

CVE-2011-2014

HIGH
9.00 CVSS 2.0

The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not examine Certificate Revocation Lists (CRLs), which allows remote authenticated users to bypass intended certificate restrictions and access Active Directory resources by leveraging a revoked X.509 certificate for a domain account, aka "LDAPS Authentication Bypass Vulnerability."

Improper Authentication
WAF: Low

CVE-2011-2004

HIGH
7.10 CVSS 2.0

Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2011-3402.

Improper Input Validation
WAF: Medium

CVE-2011-4415

LOW
1.20 CVSS 2.0

The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.

Improper Input Validation
WAF: Medium
Page 5 of 30 (1458 CVEs)