|
292991
|
- |
|
dclassifieds
|
dclassifieds
|
Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify acco…
|
CWE-352
Origin Validation Error
|
CVE-2012-0990
|
2024-11-21 10:36 |
2012-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292992
|
- |
|
apache
|
struts
|
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-s…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1007
|
2024-11-21 10:36 |
2012-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292993
|
- |
|
apache
|
struts
|
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to strut…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1006
|
2024-11-21 10:36 |
2012-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292994
|
- |
|
opera
|
opera_browser
|
Multiple integer overflows in Opera 11.60 and earlier allow remote attackers to cause a denial of service (application crash) via a large integer argument to the (1) Int32Array, (2) Float32Array, (3)…
|
CWE-189
Numeric Errors
|
CVE-2012-1003
|
2024-11-21 10:36 |
2012-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292995
|
- |
|
scriptsez
|
ez_album
|
SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
|
CWE-89
SQL Injection
|
CVE-2012-0983
|
2024-11-21 10:36 |
2012-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292996
|
- |
|
vastal
|
agent_zone
|
SQL injection vulnerability in search.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the price_from parameter.
|
CWE-89
SQL Injection
|
CVE-2012-0982
|
2024-11-21 10:36 |
2012-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292997
|
- |
|
kybernetika
|
phpshowtime
|
Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image files via a .. (dot dot) in the r parameter to index.php. NOTE: Some of these det…
|
CWE-22
Path Traversal
|
CVE-2012-0981
|
2024-11-21 10:36 |
2012-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292998
|
- |
|
phux
|
download_manager
|
SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via the file parameter.
|
CWE-89
SQL Injection
|
CVE-2012-0980
|
2024-11-21 10:36 |
2012-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292999
|
- |
|
twiki
|
twiki
|
Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field in a profile, involving (1) registration or (2) editing of …
|
CWE-79
Cross-site Scripting
|
CVE-2012-0979
|
2024-11-21 10:36 |
2012-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293000
|
- |
|
luratech
|
lurawave_jp2_browser_plug-in
|
Stack-based buffer overflow in npjp2.dll in LuraWave JP2 Browser Plug-In 1.1.1.11 and other versions before 2.1.1.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-0978
|
2024-11-21 10:36 |
2012-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|