|
292471
|
- |
|
atutor
|
acontent
|
user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5454
|
2024-11-21 10:44 |
2012-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292472
|
- |
|
atutor
|
acontent
|
SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arbitrary SQL commands via the field parameter. NOTE: this vu…
|
CWE-89
SQL Injection
|
CVE-2012-5453
|
2024-11-21 10:44 |
2012-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292473
|
- |
|
intelliants
|
subrion_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) multi_title parameter to blocks/add/; (2) cost, (3) …
|
CWE-79
Cross-site Scripting
|
CVE-2012-5452
|
2024-11-21 10:44 |
2012-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292474
|
- |
|
atutor
|
acontent
|
Multiple cross-site scripting (XSS) vulnerabilities in file_manager/preview_top.php in ATutor AContent before 1.2-2 allow remote attackers to inject arbitrary web script or HTML via the (1) pathext, …
|
CWE-79
Cross-site Scripting
|
CVE-2012-5169
|
2024-11-21 10:44 |
2012-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292475
|
- |
|
atutor
|
acontent
|
ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/index_inline_editor_submit.php or (2) course_category/index_…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5168
|
2024-11-21 10:44 |
2012-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292476
|
- |
|
atutor
|
acontent
|
Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field parameter to course_category/index_inline_editor_subm…
|
CWE-89
SQL Injection
|
CVE-2012-5167
|
2024-11-21 10:44 |
2012-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292477
|
- |
|
sun
|
sunos
|
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to inetd.
|
NVD-CWE-noinfo
|
CVE-2012-5095
|
2024-11-21 10:44 |
2012-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292478
|
- |
|
oracle
|
supply_chain_products_suite
|
Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers to affect confidentiality via unknown vectors r…
|
NVD-CWE-noinfo
|
CVE-2012-5094
|
2024-11-21 10:44 |
2012-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292479
|
- |
|
oracle
|
supply_chain_products_suite
|
Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers to affect integrity via unknown vectors related…
|
NVD-CWE-noinfo
|
CVE-2012-5093
|
2024-11-21 10:44 |
2012-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292480
|
- |
|
oracle
|
supply_chain_products_suite
|
Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote authenticated users to affect confidentiality and integri…
|
NVD-CWE-noinfo
|
CVE-2012-5092
|
2024-11-21 10:44 |
2012-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|