|
291211
|
- |
|
symantec
|
web_gateway
|
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to application scripts, related to an "injection" is…
|
CWE-78
OS Command
|
CVE-2012-2976
|
2024-11-21 10:40 |
2012-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291212
|
- |
|
symantec
|
web_gateway
|
SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2012-2961
|
2024-11-21 10:40 |
2012-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291213
|
- |
|
symantec
|
web_gateway
|
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-2957
|
2024-11-21 10:40 |
2012-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291214
|
- |
|
symantec
|
web_gateway
|
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.
|
CWE-78
OS Command
|
CVE-2012-2953
|
2024-11-21 10:40 |
2012-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291215
|
- |
|
wordpress
|
wordpress
|
WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vecto…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3385
|
2024-11-21 10:40 |
2012-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291216
|
- |
|
wordpress
|
wordpress
|
Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
|
CWE-352
Origin Validation Error
|
CVE-2012-3384
|
2024-11-21 10:40 |
2012-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291217
|
- |
|
wordpress
|
wordpress
|
The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3383
|
2024-11-21 10:40 |
2012-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291218
|
- |
|
openstack
|
essex folsom diablo
|
virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an i…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3361
|
2024-11-21 10:40 |
2012-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291219
|
- |
|
openstack
|
essex folsom
|
Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to wr…
|
CWE-22
Path Traversal
|
CVE-2012-3360
|
2024-11-21 10:40 |
2012-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291220
|
- |
|
viewvc
|
viewvc
|
The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers …
|
CWE-200
Information Exposure
|
CVE-2012-3357
|
2024-11-21 10:40 |
2012-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|