|
293041
|
6.1 |
MEDIUM
Network
|
prestashop
|
prestashop
|
PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.
|
CWE-79
Cross-site Scripting
|
CVE-2012-20001
|
2024-11-21 10:38 |
2021-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293042
|
4.8 |
MEDIUM
Network
|
wolfcms
|
wolf_cms
|
A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web script or HTML via the setting[admin_email] parameter to admin/setting.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1932
|
2024-11-21 10:38 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293043
|
5.4 |
MEDIUM
Network
|
telligent
|
community
|
XSS in Telligent Community 5.6.583.20496 via a flash file and related to the allowScriptAccess parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1903
|
2024-11-21 10:38 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293044
|
5.5 |
MEDIUM
Local
|
ibm
|
infosphere_guardium
|
InfoSphere Guardium aix_ktap module: DoS
|
NVD-CWE-noinfo
|
CVE-2012-2204
|
2024-11-21 10:38 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293045
|
5.7 |
MEDIUM
Adjacent
|
hp
|
systems_insight_manager
|
HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information
|
CWE-200
Information Exposure
|
CVE-2012-1994
|
2024-11-21 10:38 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293046
|
9.8 |
CRITICAL
Network
|
ispconfig
|
ispconfig
|
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2012-2087
|
2024-11-21 10:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293047
|
9.8 |
CRITICAL
Network
|
invisioncommunity
|
invision_power_board
|
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2012-2226
|
2024-11-21 10:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293048
|
7.8 |
HIGH
Local
|
freedesktop xpdfreader redhat opensuse
|
poppler xpdf enterprise_linux opensuse
|
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
|
NVD-CWE-Other
|
CVE-2012-2142
|
2024-11-21 10:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293049
|
6.1 |
MEDIUM
Network
|
codeigniter
|
codeigniter
|
EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1915
|
2024-11-21 10:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293050
|
7.8 |
HIGH
Local
|
redhat
|
jboss_enterprise_application_platform jboss_application_server
|
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retain…
|
CWE-269
Improper Privilege Management
|
CVE-2012-2312
|
2024-11-21 10:38 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|