|
292711
|
- |
|
netmechanica
|
netdecision
|
Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing "?" character, which causes Dashboard to attempt to ac…
|
CWE-200
Information Exposure
|
CVE-2012-1464
|
2024-11-21 10:37 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292712
|
- |
|
webgrind_project
|
webgrind
|
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parameter to index.php.
|
CWE-22
Path Traversal
|
CVE-2012-1790
|
2024-11-21 10:37 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292713
|
- |
|
tskynet
|
kongreg8
|
Multiple cross-site scripting (XSS) vulnerabilities in Kongreg8 1.7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) surname or (2) firstname parameters to modules/members/…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1789
|
2024-11-21 10:37 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292714
|
- |
|
wonderdesk
|
wonderdesk_sql
|
Multiple cross-site scripting (XSS) vulnerabilities in wonderdesk.cgi in WonderDesk SQL 4.14 allow remote attackers to inject arbitrary web script or HTML via the (1) cus_email parameter in a cust_lo…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1788
|
2024-11-21 10:37 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292715
|
- |
|
webglimpse
|
webglimpse
|
Multiple cross-site scripting (XSS) vulnerabilities in wgarcmin.cgi in Webglimpse 2.20.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) FILE, or (3) DO…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1787
|
2024-11-21 10:37 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292716
|
- |
|
kylegilman
|
video_embed_\&_thumbnail_generator
|
The Media Upload form in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to obtain the installation path via unknown vectors.
|
CWE-200
Information Exposure
|
CVE-2012-1786
|
2024-11-21 10:37 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292717
|
- |
|
kylegilman
|
video_embed_\&_thumbnail_generator
|
kg_callffmpeg.php in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to execute arbitrary commands via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2012-1785
|
2024-11-21 10:37 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292718
|
- |
|
myjoblist
|
myjoblist
|
SQL injection vulnerability in MyJobList 0.1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter in a profile action to index.php.
|
CWE-89
SQL Injection
|
CVE-2012-1784
|
2024-11-21 10:37 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292719
|
- |
|
saurabh_gupta
|
tiny_server
|
Tiny Server 1.1.9 and earlier allows remote attackers to cause a denial of service (crash) via a long string in a GET request without an HTTP version number.
|
CWE-20
Improper Input Validation
|
CVE-2012-1783
|
2024-11-21 10:37 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292720
|
- |
|
osqa
|
osqa
|
Multiple cross-site scripting (XSS) vulnerabilities in questions/ask in OSQA 3b allow remote attackers to inject arbitrary web script or HTML via the (1) url bar or (2) picture bar.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1782
|
2024-11-21 10:37 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|