|
293161
|
- |
|
symantec
|
endpoint_protection
|
The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business Edition 12.x before 12.1 RU2, does not properly v…
|
CWE-20
Improper Input Validation
|
CVE-2012-4348
|
2024-11-21 10:42 |
2012-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293162
|
- |
|
symantec
|
network_access_control
|
Unquoted Windows search path vulnerability in Symantec Network Access Control (SNAC) 12.1 before RU2 allows local users to gain privileges via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2012-4349
|
2024-11-21 10:42 |
2012-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293163
|
- |
|
symantec
|
messaging_gateway
|
Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to read arbitrary files via a .. (dot dot) in the (1)…
|
CWE-22
Path Traversal
|
CVE-2012-4347
|
2024-11-21 10:42 |
2012-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293164
|
- |
|
david_alkire
|
drag_\&_drop_gallery
|
SQL injection vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2012-4479
|
2024-11-21 10:42 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293165
|
- |
|
david_alkire
|
drag_\&_drop_gallery
|
Cross-site request forgery (CSRF) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to hijack the authentication of administrators.
|
CWE-352
Origin Validation Error
|
CVE-2012-4478
|
2024-11-21 10:42 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293166
|
- |
|
david_alkire
|
drag_\&_drop_gallery
|
Unspecified vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to bypass access restrictions via unknown attack vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4477
|
2024-11-21 10:42 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293167
|
- |
|
david_alkire
|
drag_\&_drop_gallery
|
Cross-site scripting (XSS) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-4476
|
2024-11-21 10:42 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293168
|
- |
|
security_questions_project
|
security_questions
|
The Security Questions module for Drupal 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.1 does not properly restrict access, which allows remote attackers to edit an arbitrary user's questions and a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4475
|
2024-11-21 10:42 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293169
|
- |
|
colorbox_node
|
dennis_blake
|
Multiple cross-site scripting (XSS) vulnerabilities in the Colorbox Node module 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4474
|
2024-11-21 10:42 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293170
|
- |
|
christian_johansson
|
restrict_node_page_view
|
The Restrict node page view module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "view any node page" or "view any node {type} page" permission to access unpublished no…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4473
|
2024-11-21 10:42 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|