|
295641
|
- |
|
michael_biebl
|
policykit
|
PolicyKit 0.103 sets the AdminIdentities to "wheel" by default, which allows local users in the wheel group to gain root privileges without authentication.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4945
|
2024-11-21 10:33 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295642
|
- |
|
sysprogs
|
wincdemu
|
BazisVirtualCDBus.sys in WinCDEmu 3.6 allows local users to cause a denial of service (system crash) via the unmount command to batchmnt.exe.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2011-5202
|
2024-11-21 10:33 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295643
|
- |
|
steveyolam
|
tinyguestbook
|
Multiple SQL injection vulnerabilities in sign.php in tinyguestbook allow remote attackers to execute arbitrary SQL commands via the (1) name and (2) msg parameters. NOTE: some of these details are …
|
CWE-89
SQL Injection
|
CVE-2011-5201
|
2024-11-21 10:33 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295644
|
- |
|
dedecms
|
dedecms
|
Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.
|
CWE-89
SQL Injection
|
CVE-2011-5200
|
2024-11-21 10:33 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295645
|
- |
|
steveyolam
|
tinyguestbook
|
Cross-site scripting (XSS) vulnerability in sign.php in tinyguestbook allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2011-5199
|
2024-11-21 10:33 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295646
|
- |
|
neturf
|
ecommerce_shopping_cart
|
SQL injection vulnerability in search.php in Neturf eCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the SearchFor parameter. NOTE: some of these details are obt…
|
CWE-89
SQL Injection
|
CVE-2011-5198
|
2024-11-21 10:33 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295647
|
- |
|
public_knowledge_project
|
open_harvester_systems
|
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Harvester Systems 2.3.1 and earlier allows remote attackers to hijack the authentication o…
|
CWE-352
Origin Validation Error
|
CVE-2011-5197
|
2024-11-21 10:33 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295648
|
- |
|
public_knowledge_project
|
open_journal_systems
|
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of …
|
CWE-352
Origin Validation Error
|
CVE-2011-5196
|
2024-11-21 10:33 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295649
|
- |
|
public_knowledge_project
|
open_conference_systems
|
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Conference Systems 2.3.4 and earlier allows remote attackers to hijack the authentication …
|
CWE-352
Origin Validation Error
|
CVE-2011-5195
|
2024-11-21 10:33 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295650
|
- |
|
phpace
|
samswhois
|
Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML …
|
CWE-79
Cross-site Scripting
|
CVE-2011-5194
|
2024-11-21 10:33 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|