|
296831
|
- |
|
geoff_davies
|
contact_forms
|
Cross-site scripting (XSS) vulnerability in the Contact Forms module 6.x-1.x before 6.x-1.13 for Drupal when the core contact form is enabled, allows remote authenticated users with the administer si…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2071
|
2024-11-21 10:38 |
2012-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296832
|
- |
|
andrew_levine
|
multiblock
|
Cross-site scripting (XSS) vulnerability in the MultiBlock module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer blocks permission …
|
CWE-79
Cross-site Scripting
|
CVE-2012-2070
|
2024-11-21 10:38 |
2012-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296833
|
- |
|
emil_stjerneman
|
linkit
|
The Linkit module 7.x-2.x before 7.x-2.3 for Drupal, when using an entity access module, does not check permissions when searching for entities, which allows remote attackers to obtain sensitive info…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-2304
|
2024-11-21 10:38 |
2012-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296834
|
- |
|
ubercart
|
ubercart
|
Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal allow remote authenticated users with the administer product cl…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2300
|
2024-11-21 10:38 |
2012-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296835
|
- |
|
ubercart
|
ubercart
|
The Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal stores passwords for new customers in plaintext during checkout, which allows local users to obtain sensitive informat…
|
CWE-255
Credentials Management
|
CVE-2012-2299
|
2024-11-21 10:38 |
2012-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296836
|
- |
|
drupal nancy_wichmann
|
realname
|
Multiple cross-site scripting (XSS) vulnerabilities in the RealName module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) "…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2298
|
2024-11-21 10:38 |
2012-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296837
|
- |
|
piwigo
|
piwigo
|
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Piwigo before 2.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) section parameter in the configuratio…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2209
|
2024-11-21 10:38 |
2012-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296838
|
- |
|
piwigo
|
piwigo
|
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
|
CWE-22
Path Traversal
|
CVE-2012-2208
|
2024-11-21 10:38 |
2012-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296839
|
- |
|
spip
|
spip
|
Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 allow remote attackers to inject arbitrary web script or HTML via unspec…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2151
|
2024-11-21 10:38 |
2012-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296840
|
- |
|
net-snmp
|
net-snmp
|
Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and…
|
NVD-CWE-Other
|
CVE-2012-2141
|
2024-11-21 10:38 |
2012-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|