|
289641
|
- |
|
mozilla
|
firefox thunderbird seamonkey
|
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has multiple menus of SELECT elements active, which allows …
|
NVD-CWE-Other
|
CVE-2012-5354
|
2024-11-21 10:44 |
2012-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289642
|
- |
|
eduserv
|
openathens_service_provider
|
Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."
|
CWE-287
Improper Authentication
|
CVE-2012-5353
|
2024-11-21 10:44 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289643
|
- |
|
josso
|
java_open_single_sign-on_project_home
|
Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attac…
|
CWE-287
Improper Authentication
|
CVE-2012-5352
|
2024-11-21 10:44 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289644
|
- |
|
apache
|
axis2
|
Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability tha…
|
CWE-287
Improper Authentication
|
CVE-2012-5351
|
2024-11-21 10:44 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289645
|
- |
|
wordpress
|
pay-with-tweet
|
SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the id parameter in …
|
CWE-89
SQL Injection
|
CVE-2012-5350
|
2024-11-21 10:44 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289646
|
- |
|
wordpress
|
pay-with-tweet
|
Multiple cross-site scripting (XSS) vulnerabilities in pay.php in the Pay With Tweet plugin before 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) title, or (3…
|
CWE-79
Cross-site Scripting
|
CVE-2012-5349
|
2024-11-21 10:44 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289647
|
- |
|
wilson_steven
|
mangosweb_enhanced
|
SQL injection vulnerability in MangosWeb Enhanced 3.0.3 allows remote attackers to execute arbitrary SQL commands via the login parameter in a login action to index.php.
|
CWE-89
SQL Injection
|
CVE-2012-5348
|
2024-11-21 10:44 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289648
|
- |
|
tinywebgallery
|
tinywebgallery
|
TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc or (2) info.php.
|
NVD-CWE-noinfo
|
CVE-2012-5347
|
2024-11-21 10:44 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289649
|
- |
|
bencemeszaros
|
wp-livephp
|
Cross-site scripting (XSS) vulnerability in wp-live.php in the WP Live.php module 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. NOTE: some o…
|
CWE-79
Cross-site Scripting
|
CVE-2012-5346
|
2024-11-21 10:44 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289650
|
- |
|
kepler_lam
|
iptools
|
Buffer overflow in the Remote command server (Rcmd.bat) in IpTools (aka Tiny TCP/IP server) 0.1.4 allows remote attackers to cause a denial of service (crash) via a long string to TCP port 23.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-5345
|
2024-11-21 10:44 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|