|
288511
|
6.5 |
MEDIUM
Network
|
netgear
|
wgr614v9_firmware wgr614v7_firmware
|
An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the co…
|
CWE-200
Information Exposure
|
CVE-2012-6341
|
2024-11-21 10:46 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288512
|
4.6 |
MEDIUM
Physics
|
netgear
|
wgr614v9_firmware wgr614v7_firmware
|
An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial programming, a related issue to CVE-2006-1002.
|
CWE-287
Improper Authentication
|
CVE-2012-6340
|
2024-11-21 10:46 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288513
|
5.4 |
MEDIUM
Network
|
havalite
|
havalite
|
Havalite CMS 1.1.7 has a stored XSS vulnerability
|
CWE-79
Cross-site Scripting
|
CVE-2013-0161
|
2024-11-21 10:46 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288514
|
8.8 |
HIGH
Network
|
polycom
|
hdx_video_end_points uc_apl
|
Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping command feature.
|
CWE-78
OS Command
|
CVE-2012-6610
|
2024-11-21 10:46 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288515
|
7.5 |
HIGH
Network
|
polycom
|
hdx_video_end_points uc_apl
|
Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name…
|
CWE-22
Path Traversal
|
CVE-2012-6609
|
2024-11-21 10:46 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288516
|
6.1 |
MEDIUM
Network
|
cpanel
|
webhost_manager
|
Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6448
|
2024-11-21 10:46 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288517
|
7.2 |
HIGH
Network
|
dlink
|
dsr-250n_firmware
|
D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.
|
NVD-CWE-noinfo
|
CVE-2012-6613
|
2024-11-21 10:46 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288518
|
6.1 |
MEDIUM
Network
|
rapid7
|
nexpose
|
Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorized access.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6494
|
2024-11-21 10:46 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288519
|
7.5 |
HIGH
Network
|
novell
|
zenworks_configuration_management
|
Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.
|
NVD-CWE-noinfo
|
CVE-2012-6345
|
2024-11-21 10:46 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288520
|
6.1 |
MEDIUM
Network
|
novell
|
zenworks_configuration_management
|
Novell ZENworks Configuration Management before 11.2.4 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6344
|
2024-11-21 10:46 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|