|
294371
|
- |
|
sitracker
|
support_incident_tracker
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijack the authentication of administrators for requests that c…
|
CWE-352
Origin Validation Error
|
CVE-2011-5074
|
2024-11-21 10:33 |
2012-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294372
|
- |
|
sitracker
|
support_incident_tracker
|
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to execute arbitrary SQL commands via the (1) start parameter to portal/kb.php; (2) co…
|
CWE-89
SQL Injection
|
CVE-2011-5072
|
2024-11-21 10:33 |
2012-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294373
|
- |
|
sitracker
|
support_incident_tracker
|
Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to inject arbitrary web script or HTML via the (1) mode parameter to cont…
|
CWE-79
Cross-site Scripting
|
CVE-2011-5073
|
2024-11-21 10:33 |
2012-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294374
|
- |
|
sitracker
|
support_incident_tracker
|
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL commands via the (1) exc[] parameter to report_marketing.php,…
|
CWE-89
SQL Injection
|
CVE-2011-5071
|
2024-11-21 10:33 |
2012-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294375
|
- |
|
sitracker
|
support_incident_tracker
|
Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to inject arbitrary web script or HTML via (1) the file name to incident_attachm…
|
CWE-79
Cross-site Scripting
|
CVE-2011-5070
|
2024-11-21 10:33 |
2012-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294376
|
- |
|
sitracker
|
support_incident_tracker
|
Unrestricted file upload vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to execute arbitrary code by uploading a file with an …
|
NVD-CWE-Other
|
CVE-2011-5069
|
2024-11-21 10:33 |
2012-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294377
|
- |
|
sitracker
|
support_incident_tracker
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to hijack the authentication of user for requests that delete a user via …
|
CWE-352
Origin Validation Error
|
CVE-2011-5068
|
2024-11-21 10:33 |
2012-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294378
|
- |
|
sitracker
|
support_incident_tracker
|
move_uploaded_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation path in an error…
|
CWE-200
Information Exposure
|
CVE-2011-5067
|
2024-11-21 10:33 |
2012-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294379
|
- |
|
tencent
|
qqpphoto
|
The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a password hash via a cr…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4867
|
2024-11-21 10:33 |
2012-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294380
|
- |
|
kaixin001
|
kaixin001
|
The Kaixin001 (com.kaixin001.activity) application 1.3.1 and 1.3.3 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a cleartext pass…
|
CWE-200
Information Exposure
|
CVE-2011-4866
|
2024-11-21 10:33 |
2012-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|