|
293541
|
- |
|
s9y
|
serendipity
|
Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the serendi…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2331
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293542
|
- |
|
nodejs
|
nodejs
|
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive informatio…
|
CWE-20
Improper Input Validation
|
CVE-2012-2330
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293543
|
- |
|
pivotx
|
pivotx
|
Cross-site scripting (XSS) vulnerability in pivotx/ajaxhelper.php in PivotX 2.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the file parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-2274
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293544
|
- |
|
mnt-tech
|
wp-facethumb
|
Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pagination_wp_facethumb param…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2371
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293545
|
- |
|
gnome
|
gdk-pixbuf
|
Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) hei…
|
CWE-189
Numeric Errors
|
CVE-2012-2370
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293546
|
- |
|
bytemark
|
symbiosis
|
Bytemark Symbiosis before Revision 1322 does not properly validate passwords, which allows remote attackers to gain access to email accounts via an arbitrary password.
|
CWE-20
Improper Input Validation
|
CVE-2012-2368
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293547
|
- |
|
mybb
|
mybb
|
MyBB (aka MyBulletinBoard) before 1.6.7 allows remote attackers to obtain sensitive information via a malformed forumread cookie, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2012-2327
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293548
|
- |
|
mybb
|
mybb
|
Cross-site scripting (XSS) vulnerability in the Admin Control Panel (ACP) in MyBB (aka MyBulletinBoard) before 1.6.7 allows remote administrators to inject arbitrary web script or HTML via a malforme…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2326
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293549
|
- |
|
mybb
|
mybb
|
SQL injection vulnerability in the User Inline Moderation feature in the Admin Control Panel (ACP) in MyBB (aka MyBulletinBoard) before 1.6.7 allows remote administrators to execute arbitrary SQL com…
|
CWE-89
SQL Injection
|
CVE-2012-2325
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293550
|
- |
|
mybb
|
mybb
|
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.7 allow remote administrators to execute arbitrary SQL commands via unspecified vectors in the (1) user search or (2) M…
|
CWE-89
SQL Injection
|
CVE-2012-2324
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|