|
291911
|
7.5 |
HIGH
Network
|
ibm
|
websphere_mq
|
IBM WebSphere MQ 7.1 is vulnerable to a denial of service, caused by an error when handling user ids. A remote attacker could exploit this vulnerability to bypass the security configuration setup on …
|
NVD-CWE-noinfo
|
CVE-2012-2201
|
2024-11-21 10:38 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291912
|
6.1 |
MEDIUM
Network
|
ibm
|
rational_change
|
IBM Rational Change 5.3 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using the SUPP_TEMPLATE_FLAG pa…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2160
|
2024-11-21 10:38 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291913
|
6.1 |
MEDIUM
Network
|
prestashop
|
prestashop
|
PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.
|
CWE-79
Cross-site Scripting
|
CVE-2012-20001
|
2024-11-21 10:38 |
2021-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291914
|
4.8 |
MEDIUM
Network
|
wolfcms
|
wolf_cms
|
A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web script or HTML via the setting[admin_email] parameter to admin/setting.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1932
|
2024-11-21 10:38 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291915
|
5.4 |
MEDIUM
Network
|
telligent
|
community
|
XSS in Telligent Community 5.6.583.20496 via a flash file and related to the allowScriptAccess parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1903
|
2024-11-21 10:38 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291916
|
5.5 |
MEDIUM
Local
|
ibm
|
infosphere_guardium
|
InfoSphere Guardium aix_ktap module: DoS
|
NVD-CWE-noinfo
|
CVE-2012-2204
|
2024-11-21 10:38 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291917
|
5.7 |
MEDIUM
Adjacent
|
hp
|
systems_insight_manager
|
HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information
|
CWE-200
Information Exposure
|
CVE-2012-1994
|
2024-11-21 10:38 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291918
|
9.8 |
CRITICAL
Network
|
ispconfig
|
ispconfig
|
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2012-2087
|
2024-11-21 10:38 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291919
|
9.8 |
CRITICAL
Network
|
invisioncommunity
|
invision_power_board
|
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2012-2226
|
2024-11-21 10:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291920
|
7.8 |
HIGH
Local
|
freedesktop xpdfreader redhat opensuse
|
poppler xpdf enterprise_linux opensuse
|
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
|
NVD-CWE-Other
|
CVE-2012-2142
|
2024-11-21 10:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|