|
288421
|
- |
|
danielb
|
finder
|
Cross-site scripting (XSS) vulnerability in the autocomplete functionality in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers …
|
CWE-79
Cross-site Scripting
|
CVE-2012-6645
|
2024-11-21 10:46 |
2014-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288422
|
- |
|
clip-bucket
|
clipbucket
|
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3)…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6644
|
2024-11-21 10:46 |
2014-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288423
|
- |
|
clip-bucket
|
clipbucket
|
Multiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow remote attackers to execute arbitrary SQL commands via the time parameter to (1…
|
CWE-89
SQL Injection
|
CVE-2012-6643
|
2024-11-21 10:46 |
2014-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288424
|
- |
|
clip-bucket
|
clipbucket
|
Cross-site scripting (XSS) vulnerability in ClipBucket 2.6 allows remote attackers to inject arbitrary web script or HTML via the type parameter to view_channel.php. NOTE: the provenance of this inf…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6642
|
2024-11-21 10:46 |
2014-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288425
|
- |
|
prestashop
|
prestashop
|
Cross-site scripting (XSS) vulnerability in redirect.php in the Socolissimo module (modules/socolissimo/) in PrestaShop before 1.4.7.2 allows remote attackers to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6641
|
2024-11-21 10:46 |
2014-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288426
|
- |
|
horde
|
groupware imp
|
Cross-site scripting (XSS) vulnerability in Horde Internet Mail Program (IMP) before 5.0.22, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web s…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6640
|
2024-11-21 10:46 |
2014-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288427
|
- |
|
samsung
|
kies
|
Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to execute arbitrary code via a long string to the pass…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-6429
|
2024-11-21 10:46 |
2014-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288428
|
- |
|
opensolution
|
quick_cart quick_cms
|
Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded before December 19, 2012, allows remote attackers to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2012-6430
|
2024-11-21 10:46 |
2014-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288429
|
- |
|
mongodb
|
mongodb
|
The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to cause a denial of service (crash) or read system memory via a crafted BSON obj…
|
CWE-20
Improper Input Validation
|
CVE-2012-6619
|
2024-11-21 10:46 |
2014-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288430
|
- |
|
apache adobe
|
cordova phonegap
|
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist protection mechanis…
|
CWE-20
Improper Input Validation
|
CVE-2012-6637
|
2024-11-21 10:46 |
2014-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|