|
295781
|
- |
|
apache
|
wicket
|
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-0047
|
2024-11-21 10:34 |
2012-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295782
|
- |
|
rsa
|
envision
|
Directory traversal vulnerability in EMC RSA enVision 4.x before 4.1 Patch 4 allows remote authenticated users to have an unspecified impact via unknown vectors.
|
CWE-22
Path Traversal
|
CVE-2012-0403
|
2024-11-21 10:34 |
2012-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295783
|
- |
|
rsa
|
envision
|
EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access via unknown vectors.
|
CWE-255
Credentials Management
|
CVE-2012-0402
|
2024-11-21 10:34 |
2012-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295784
|
- |
|
rsa
|
envision
|
Multiple SQL injection vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2012-0401
|
2024-11-21 10:34 |
2012-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295785
|
- |
|
rsa
|
envision
|
EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
|
CWE-287
Improper Authentication
|
CVE-2012-0400
|
2024-11-21 10:34 |
2012-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295786
|
- |
|
rsa
|
envision
|
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-0399
|
2024-11-21 10:34 |
2012-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295787
|
- |
|
janetter
|
janetter
|
Janetter before 3.3.0.0 (aka 3.3.0) allows remote attackers to obtain session information for twitter.com web sites via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2012-0328
|
2024-11-21 10:34 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295788
|
- |
|
golismero
|
golismero
|
libs/updater.py in GoLismero 0.6.3, and other versions before Git revision 2b3bb43d6867, as used in backtrack and possibly other products, allows local users to overwrite arbitrary files via a symlin…
|
CWE-59
Link Following
|
CVE-2012-0054
|
2024-11-21 10:34 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295789
|
- |
|
tetsuya_aoyama
|
twicca
|
The twicca application 0.7.0 through 0.9.30 for Android does not properly restrict the use of network privileges, which allows remote attackers to read media files on an SD card via a crafted applica…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-0326
|
2024-11-21 10:34 |
2012-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295790
|
- |
|
symantec
|
altiris_wise_package_studio
|
Multiple SQL injection vulnerabilities in Symantec Altiris WISE Package Studio before 8.0MR1 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2012-0293
|
2024-11-21 10:34 |
2012-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|