|
293621
|
- |
|
x7_group
|
x7_chat
|
Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that add a user to an arbitrary grou…
|
CWE-352
Origin Validation Error
|
CVE-2012-6047
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293622
|
- |
|
phpenter
|
php_enter
|
Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php via the code parameter.
|
CWE-94
Code Injection
|
CVE-2012-6046
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293623
|
- |
|
ramui
|
ramui_forum
|
Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers to inject arbitrary web script or HTML via the query parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6045
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293624
|
- |
|
mjsware
|
m-player
|
M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file.
|
CWE-20
Improper Input Validation
|
CVE-2012-6044
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293625
|
- |
|
php-fusion
|
php-fusion
|
Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6043
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293626
|
- |
|
geopainting
|
gpsmapedit
|
GPSMapEdit 1.1.73.2 allows user-assisted remote attackers to cause a denial of service (crash) via a long string in a lst file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-6042
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293627
|
- |
|
morequick
|
greenbrowser
|
Double free vulnerability in GreenBrowser before 6.0.1002, when the keyword search bar (F6) is activated, allows remote attackers to execute arbitrary code via a crafted iframe.
|
CWE-399
Resource Management Errors
|
CVE-2012-6041
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293628
|
- |
|
convergine
|
file_king_advanced_file_management
|
Cross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6040
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293629
|
- |
|
yabsoft
|
advanced_image_hosting_script
|
SQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows remote attackers to execute arbitrary SQL commands via the gal parameter.
|
CWE-89
SQL Injection
|
CVE-2012-6039
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293630
|
- |
|
razorcms
|
razorcms
|
admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remote authenticated users to read, edit, rename, mov…
|
CWE-22
Path Traversal
|
CVE-2012-6038
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|