|
291881
|
- |
|
pluxml
|
pluxml
|
Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the default_la…
|
CWE-22
Path Traversal
|
CVE-2012-2227
|
2024-11-21 10:38 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291882
|
- |
|
emc
|
applicationxtender_web_access_.net applicationxtender_desktop
|
EMC ApplicationXtender Desktop before 6.5 SP2 and ApplicationXtender Web Access .NET before 6.5 SP2 allow remote attackers to upload files to any location, and possibly execute arbitrary code, via un…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-2289
|
2024-11-21 10:38 |
2012-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291883
|
- |
|
ibm
|
websphere_application_server
|
IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1,…
|
CWE-310
Cryptographic Issues
|
CVE-2012-2190
|
2024-11-21 10:38 |
2012-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291884
|
- |
|
debian
|
devotee
|
devotee 0.1 patch 2 uses a 32-bit seed for generating 48-bit random numbers, which makes it easier for remote attackers to obtain the secret monikers via a brute force attack.
|
CWE-200
Information Exposure
|
CVE-2012-2387
|
2024-11-21 10:38 |
2012-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291885
|
- |
|
gnome
|
libsoup
|
libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL …
|
CWE-287
Improper Authentication
|
CVE-2012-2132
|
2024-11-21 10:38 |
2012-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291886
|
- |
|
ibm
|
rational_clearquest
|
Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a workspac…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2205
|
2024-11-21 10:38 |
2012-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291887
|
- |
|
ibm
|
rational_clearquest
|
Cross-site scripting (XSS) vulnerability in the file-upload functionality in the Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 allows remote authenticated users to inject arbitrary web s…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2169
|
2024-11-21 10:38 |
2012-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291888
|
- |
|
ibm
|
rational_clearquest
|
IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to obtain sensitive stack-trace information from CM server error messages via an invalid paramete…
|
CWE-200
Information Exposure
|
CVE-2012-2168
|
2024-11-21 10:38 |
2012-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291889
|
- |
|
ibm
|
rational_clearquest
|
IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3, when ClearQuest Authentication is enabled, allows remote authenticated users to read password hashes via a user query.
|
CWE-200
Information Exposure
|
CVE-2012-2165
|
2024-11-21 10:38 |
2012-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291890
|
- |
|
ibm
|
rational_clearquest
|
The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access restrictions, and use the Site Administration menu to…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-2164
|
2024-11-21 10:38 |
2012-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|