|
293121
|
- |
|
atmail
|
atmail_open
|
Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allow remote attackers to read arbitrary file…
|
CWE-22
Path Traversal
|
CVE-2012-1918
|
2024-11-21 10:38 |
2012-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293122
|
- |
|
atmail
|
atmail_open
|
compose.php in @Mail WebMail Client in AtMail Open-Source before 1.05 does not properly handle ../ (dot dot slash) sequences in the unique parameter, which allows remote attackers to conduct director…
|
CWE-22
Path Traversal
|
CVE-2012-1917
|
2024-11-21 10:38 |
2012-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293123
|
- |
|
atmail
|
atmail_open
|
@Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to execute arbitrary code via an e-mail attachment with an executable extension, leading to the creation of an executabl…
|
NVD-CWE-Other
|
CVE-2012-1916
|
2024-11-21 10:38 |
2012-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293124
|
5.4 |
MEDIUM
Network
|
atlassian
|
jira greenhopper
|
Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1500
|
2024-11-21 10:37 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293125
|
7.5 |
HIGH
Network
|
linuxmint
|
linuxmint
|
LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintUpdate.
|
NVD-CWE-noinfo
|
CVE-2012-1567
|
2024-11-21 10:37 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293126
|
7.5 |
HIGH
Network
|
linuxmint
|
linuxmint
|
LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintNanny.
|
NVD-CWE-noinfo
|
CVE-2012-1566
|
2024-11-21 10:37 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293127
|
8.8 |
HIGH
Network
|
webcalendar_project
|
webcalendar
|
Local file inclusion in WebCalendar before 1.2.5.
|
CWE-74
Injection
|
CVE-2012-1496
|
2024-11-21 10:37 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293128
|
9.8 |
CRITICAL
Network
|
webcalendar_project
|
webcalendar
|
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
|
CWE-74
Injection
|
CVE-2012-1495
|
2024-11-21 10:37 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293129
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
Joomla! before 2.5.3 allows Admin Account Creation.
|
CWE-269
Improper Privilege Management
|
CVE-2012-1563
|
2024-11-21 10:37 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293130
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
Joomla! core before 2.5.3 allows unauthorized password change.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2012-1562
|
2024-11-21 10:37 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|