|
292251
|
- |
|
nextbbs
|
nextbbs
|
Cross-site scripting (XSS) vulnerability in NextBBS 0.6 allows remote attackers to inject arbitrary web script or HTML via the do parameter to index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1604
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292252
|
- |
|
nextbbs
|
nextbbs
|
Multiple SQL injection vulnerabilities in ajaxserver.php in NextBBS 0.6 allow remote attackers to execute arbitrary SQL commands via the (1) curstr parameter in the findUsers function, (2) id paramet…
|
CWE-89
SQL Injection
|
CVE-2012-1603
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292253
|
- |
|
nextbbs
|
nextbbs
|
user.php in NextBBS 0.6 allows remote attackers to bypass authentication and gain administrator access by setting the userkey cookie to 1.
|
CWE-287
Improper Authentication
|
CVE-2012-1602
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292254
|
- |
|
ocportal
|
ocportal
|
Directory traversal vulnerability in catalogue_file.php in ocPortal before 7.1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
|
CWE-22
Path Traversal
|
CVE-2012-1471
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292255
|
- |
|
ocportal
|
ocportal
|
Multiple cross-site scripting (XSS) vulnerabilities in code_editor.php in ocPortal before 7.1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) path or (2) line parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1470
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292256
|
- |
|
luke_herrington
|
stickynote
|
Cross-site request forgery (CSRF) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of users for requests that delete stickynotes v…
|
CWE-352
Origin Validation Error
|
CVE-2012-1636
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292257
|
- |
|
commerceguys
|
commerce
|
Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1639
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292258
|
- |
|
atheme
|
atheme
|
The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly clean up CertFP entries when a user is deleted, which…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1576
|
2024-11-21 10:37 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292259
|
- |
|
drupal
|
drupal
|
The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1591
|
2024-11-21 10:37 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292260
|
- |
|
drupal
|
drupal
|
The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1590
|
2024-11-21 10:37 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|