|
290611
|
- |
|
sayakbanerjee
|
sticky_notes
|
Multiple cross-site scripting (XSS) vulnerabilities in Sticky Notes before 0.2.27052012.5 allow remote attackers to inject arbitrary web script or HTML via the (1) paste_user or (2) paste_lang parame…
|
CWE-79
Cross-site Scripting
|
CVE-2012-3997
|
2024-11-21 10:42 |
2012-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290612
|
- |
|
tiki
|
tikiwiki_cms\/groupware
|
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_se…
|
CWE-200
Information Exposure
|
CVE-2012-3996
|
2024-11-21 10:42 |
2012-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290613
|
4.3 |
MEDIUM
Network
|
arialsoftware
|
campaign_enterprise
|
A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber field.
|
CWE-863
Incorrect Authorization
|
CVE-2012-3821
|
2024-11-21 10:41 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290614
|
7.5 |
HIGH
Network
|
arialsoftware
|
campaign_enterprise
|
In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.
|
CWE-287
Improper Authentication
|
CVE-2012-3824
|
2024-11-21 10:41 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290615
|
7.5 |
HIGH
Network
|
arialsoftware
|
campaign_enterprise
|
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2012-3823
|
2024-11-21 10:41 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290616
|
7.5 |
HIGH
Network
|
arialsoftware
|
campaign_enterprise
|
Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials.
|
CWE-863
Incorrect Authorization
|
CVE-2012-3822
|
2024-11-21 10:41 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290617
|
7.5 |
HIGH
Network
|
samsung
|
kies
|
Samsung Kies before 2.5.0.12094_27_11 has registry modification.
|
NVD-CWE-noinfo
|
CVE-2012-3810
|
2024-11-21 10:41 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290618
|
7.5 |
HIGH
Network
|
samsung
|
kies
|
Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.
|
NVD-CWE-noinfo
|
CVE-2012-3809
|
2024-11-21 10:41 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290619
|
7.5 |
HIGH
Network
|
samsung
|
kies
|
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.
|
NVD-CWE-noinfo
|
CVE-2012-3808
|
2024-11-21 10:41 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290620
|
9.8 |
CRITICAL
Network
|
samsung
|
kies
|
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.
|
NVD-CWE-noinfo
|
CVE-2012-3807
|
2024-11-21 10:41 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|