|
290301
|
- |
|
matthias_hutterer
|
email
|
The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to email the stored address in the entity via unspecified vec…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4499
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290302
|
- |
|
inclind
|
custom_pub
|
Cross-site scripting (XSS) vulnerability in the Custom Publishing Options module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer nodes" permission to inject a…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4496
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290303
|
- |
|
mime_mail_module_project
|
mimemail
|
The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary f…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4495
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290304
|
- |
|
niif
|
shibb_auth
|
The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access restrictions and possibl…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4494
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290305
|
- |
|
isaac_sukin
|
shorten
|
Multiple cross-site scripting (XSS) vulnerabilities in the Shorten URLs module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions …
|
CWE-79
Cross-site Scripting
|
CVE-2012-4492
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290306
|
- |
|
tomatocart
|
tomatocart
|
TomatoCart 1.1.7, when the PayPal Express Checkout module is enabled in sandbox mode, allows remote authenticated users to bypass intended payment requirements by modifying a certain redirection URL.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4934
|
2024-11-21 10:43 |
2012-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290307
|
- |
|
emc
|
avamar
|
EMC Avamar Client for VMware 6.1 stores the cleartext server root password on the proxy client, which might allow remote attackers to obtain sensitive information by leveraging "network access" to th…
|
CWE-255
Credentials Management
|
CVE-2012-4610
|
2024-11-21 10:43 |
2012-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290308
|
- |
|
laurent_destailleur
|
awstats
|
Unspecified vulnerability in awredir.pl in AWStats before 7.1 has unknown impact and attack vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-4547
|
2024-11-21 10:43 |
2012-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290309
|
- |
|
cisco
|
adaptive_security_appliance_software 5500_series_adaptive_security_appliance 7600_router catalyst_6500 catalyst_6503-e catalyst_6504-e catalyst_6506-e catalyst_6509-e catalyst…
|
The DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-4663
|
2024-11-21 10:43 |
2012-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290310
|
- |
|
wftpserver
|
wing_ftp_server
|
Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-4729
|
2024-11-21 10:43 |
2012-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|