|
292741
|
- |
|
apache
|
cxf
|
Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element …
|
NVD-CWE-noinfo
|
CVE-2012-2379
|
2024-11-21 10:38 |
2013-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292742
|
- |
|
mahara
|
mahara
|
Cross-site scripting (XSS) vulnerability in group/members.php in Mahara 1.5.x before 1.5.7 and 1.6.x before 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the query paramete…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2253
|
2024-11-21 10:38 |
2012-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292743
|
- |
|
mahara
|
mahara
|
Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to artefact/file/ and a…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2247
|
2024-11-21 10:38 |
2012-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292744
|
- |
|
mahara
|
mahara
|
Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to conduct clickjacking attacks to delete arbitrary users and bypass CSRF protection via account/delete.php.
|
CWE-20
Improper Input Validation
|
CVE-2012-2246
|
2024-11-21 10:38 |
2012-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292745
|
- |
|
mahara
|
mahara
|
Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to clamav. NOTE: this can be exploited without authent…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-2244
|
2024-11-21 10:38 |
2012-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292746
|
- |
|
mahara
|
mahara
|
Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML by uploading an XML file with the xhtml ext…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2243
|
2024-11-21 10:38 |
2012-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292747
|
9.1 |
CRITICAL
Network
|
mahara debian
|
mahara debian_linux
|
Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by readin…
|
CWE-611
XXE
|
CVE-2012-2239
|
2024-11-21 10:38 |
2012-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292748
|
- |
|
redhat
|
jboss_enterprise_portal_platform jboss_enterprise_soa_platform jboss_enterprise_brms_platform
|
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups …
|
CWE-287
Improper Authentication
|
CVE-2012-2377
|
2024-11-21 10:38 |
2012-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292749
|
- |
|
gajim
|
gajim
|
SQL injection vulnerability in the get_last_conversation_lines function in common/logger.py in Gajim before 0.15 allows remote attackers to execute arbitrary SQL commands via the jig parameter.
|
CWE-89
SQL Injection
|
CVE-2012-2086
|
2024-11-21 10:38 |
2012-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292750
|
- |
|
egroupware
|
egroupware
|
Cross-site scripting (XSS) vulnerability in phpgwapi/inc/common_functions_inc.php in eGroupware before 1.8.004.20120405 allows remote attackers to inject arbitrary web script or HTML via the menuacti…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2211
|
2024-11-21 10:38 |
2012-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|