|
292051
|
7.5 |
HIGH
Network
|
polycom
|
hdx_video_end_points uc_apl
|
Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name…
|
CWE-22
Path Traversal
|
CVE-2012-6609
|
2024-11-21 10:46 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292052
|
6.1 |
MEDIUM
Network
|
cpanel
|
webhost_manager
|
Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6448
|
2024-11-21 10:46 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292053
|
7.2 |
HIGH
Network
|
dlink
|
dsr-250n_firmware
|
D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.
|
NVD-CWE-noinfo
|
CVE-2012-6613
|
2024-11-21 10:46 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292054
|
6.1 |
MEDIUM
Network
|
rapid7
|
nexpose
|
Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorized access.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6494
|
2024-11-21 10:46 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292055
|
7.5 |
HIGH
Network
|
novell
|
zenworks_configuration_management
|
Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.
|
NVD-CWE-noinfo
|
CVE-2012-6345
|
2024-11-21 10:46 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292056
|
6.1 |
MEDIUM
Network
|
novell
|
zenworks_configuration_management
|
Novell ZENworks Configuration Management before 11.2.4 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6344
|
2024-11-21 10:46 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292057
|
9.8 |
CRITICAL
Network
|
lorextechnology
|
lnc116_firmware lnc104_firmware
|
Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability
|
CWE-287
Improper Authentication
|
CVE-2012-6451
|
2024-11-21 10:46 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292058
|
7.5 |
HIGH
Network
|
ge
|
d20me_firmware d200_firmware
|
General Electric D20ME devices are not properly configured and reveal plaintext passwords.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2012-6663
|
2024-11-21 10:46 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292059
|
9.8 |
CRITICAL
Network
|
devfarm
|
wp_gpx_maps
|
WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2012-6649
|
2024-11-21 10:46 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292060
|
5.5 |
MEDIUM
Local
|
redhat
|
openshift
|
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2013-0163
|
2024-11-21 10:46 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|