|
290441
|
- |
|
mindjet
|
mindmanager_2012
|
Multiple untrusted search path vulnerabilities in MindManager 2012 10.0.493 allow local users to gain privileges via a Trojan horse (1) ssgp.dll or (2) dwmapi.dll file in the current working director…
|
NVD-CWE-Other
|
CVE-2012-4754
|
2024-11-21 10:43 |
2012-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290442
|
- |
|
owncloud
|
owncloud
|
Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.5 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
|
CWE-352
Origin Validation Error
|
CVE-2012-4753
|
2024-11-21 10:43 |
2012-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290443
|
- |
|
owncloud
|
owncloud
|
appconfig.php in ownCloud before 4.0.6 does not properly restrict access, which allows remote authenticated users to edit app configurations via unspecified vectors. NOTE: this can be leveraged by u…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4752
|
2024-11-21 10:43 |
2012-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290444
|
- |
|
mozilla
|
bugzilla
|
Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive information under the web root with insufficient a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4747
|
2024-11-21 10:43 |
2012-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290445
|
- |
|
zte
|
zxdsl
|
Cross-site request forgery (CSRF) vulnerability in accessaccount.cgi in ZTE ZXDSL 831IIV7.5.0a_Z29_OV allows remote attackers to hijack the authentication of administrators for requests that change t…
|
CWE-352
Origin Validation Error
|
CVE-2012-4746
|
2024-11-21 10:43 |
2012-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290446
|
- |
|
the_collective
|
acuity_cms
|
Cross-site scripting (XSS) vulnerability in admin/login.asp in Acuity CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-4745
|
2024-11-21 10:43 |
2012-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290447
|
- |
|
eos.pe
|
siche_search_module
|
Cross-site scripting (XSS) vulnerability in ssearch.php in the Siche search module 0.5 for Zeroboard allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-4744
|
2024-11-21 10:43 |
2012-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290448
|
- |
|
eos.pe
|
siche_search_module
|
Multiple SQL injection vulnerabilities in ssearch.php in Siche search module 0.5 for Zeroboard allow remote attackers to execute arbitrary SQL commands via the (1) ss, (2) sm, (3) align, or (4) categ…
|
CWE-89
SQL Injection
|
CVE-2012-4743
|
2024-11-21 10:43 |
2012-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290449
|
- |
|
packetfence
|
packetfence
|
The web_node_register function in web.pm in PacketFence before 3.0.2 might allow remote attackers to execute arbitrary code via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2012-4742
|
2024-11-21 10:43 |
2012-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290450
|
- |
|
packetfence
|
packetfence
|
The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assignment extensions, which allows remote attackers to spoof us…
|
CWE-287
Improper Authentication
|
CVE-2012-4741
|
2024-11-21 10:43 |
2012-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|