|
292421
|
- |
|
nextbbs
|
nextbbs
|
user.php in NextBBS 0.6 allows remote attackers to bypass authentication and gain administrator access by setting the userkey cookie to 1.
|
CWE-287
Improper Authentication
|
CVE-2012-1602
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292422
|
- |
|
ocportal
|
ocportal
|
Directory traversal vulnerability in catalogue_file.php in ocPortal before 7.1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
|
CWE-22
Path Traversal
|
CVE-2012-1471
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292423
|
- |
|
ocportal
|
ocportal
|
Multiple cross-site scripting (XSS) vulnerabilities in code_editor.php in ocPortal before 7.1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) path or (2) line parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1470
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292424
|
- |
|
luke_herrington
|
stickynote
|
Cross-site request forgery (CSRF) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of users for requests that delete stickynotes v…
|
CWE-352
Origin Validation Error
|
CVE-2012-1636
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292425
|
- |
|
commerceguys
|
commerce
|
Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1639
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292426
|
- |
|
atheme
|
atheme
|
The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly clean up CertFP entries when a user is deleted, which…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1576
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292427
|
- |
|
drupal
|
drupal
|
The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1591
|
2024-11-21 10:37 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292428
|
- |
|
drupal
|
drupal
|
The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1590
|
2024-11-21 10:37 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292429
|
- |
|
drupal
|
drupal
|
Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain r…
|
CWE-399
Resource Management Errors
|
CVE-2012-1588
|
2024-11-21 10:37 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292430
|
- |
|
springsource
|
grails
|
VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1833
|
2024-11-21 10:37 |
2012-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|