|
292191
|
8.8 |
HIGH
Network
|
apache
|
struts
|
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2012-1592
|
2024-11-21 10:37 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292192
|
4.8 |
MEDIUM
Network
|
drupal
|
quick_tabs
|
Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1637
|
2024-11-21 10:37 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292193
|
7.5 |
HIGH
Network
|
openstack debian
|
keystone debian_linux
|
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2012-1572
|
2024-11-21 10:37 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292194
|
9.8 |
CRITICAL
Network
|
apache
|
ofbiz
|
Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2012-1622
|
2024-11-21 10:37 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292195
|
- |
|
oscmax
|
oscmax
|
Multiple SQL injection vulnerabilities in the admin panel in osCMax before 2.5.1 allow (1) remote attackers to execute arbitrary SQL commands via the username parameter in a process action to admin/l…
|
CWE-89
SQL Injection
|
CVE-2012-1665
|
2024-11-21 10:37 |
2015-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292196
|
- |
|
oscmax
|
oscmax
|
Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in a process…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1664
|
2024-11-21 10:37 |
2015-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292197
|
- |
|
phpmoneybooks
|
phpmoneybooks
|
Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.
|
CWE-22
Path Traversal
|
CVE-2012-1669
|
2024-11-21 10:37 |
2014-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292198
|
- |
|
orangehrm
|
orangehrm
|
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plugins/ajaxCalls/haltR…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1507
|
2024-11-21 10:37 |
2014-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292199
|
- |
|
orangehrm
|
orangehrm
|
SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryI…
|
CWE-89
SQL Injection
|
CVE-2012-1506
|
2024-11-21 10:37 |
2014-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292200
|
- |
|
synology
|
diskstation_manager synology_photo_station
|
Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to ph…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1556
|
2024-11-21 10:37 |
2014-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|