|
295001
|
- |
|
cisco
|
small_business_srp521w small_business_srp526w small_business_srp527w small_business_srp520_series_firmware small_business_srp541w small_business_srp546w small_business_srp547w sm…
|
Cross-site request forgery (CSRF) vulnerability in the Services Ready Platform Configuration Utility web interface on the Cisco Small Business SRP521W, SRP526W, and SRP527W with firmware before 1.1.2…
|
CWE-352
Origin Validation Error
|
CVE-2011-4005
|
2024-11-21 10:31 |
2011-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295002
|
- |
|
phpldapadmin_project
|
phpldapadmin
|
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine act…
|
CWE-94
Code Injection
|
CVE-2011-4075
|
2024-11-21 10:31 |
2011-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295003
|
- |
|
phpldapadmin_project
|
phpldapadmin
|
Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4074
|
2024-11-21 10:31 |
2011-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295004
|
- |
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4064
|
2024-11-21 10:31 |
2011-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295005
|
- |
|
cisco
|
webex_recording_format_player
|
Buffer overflow in the ATAS32 processing functionality in the Cisco WebEx Recording Format (WRF) player T26 before SP49 EP40 and T27 before SP28 allows remote attackers to execute arbitrary code via …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2011-4004
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295006
|
- |
|
openldap
|
openldap
|
Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and earlier allows remote attackers to cause a denial of service (slapd crash) via a zero-length string that triggers a heap-ba…
|
CWE-189
Numeric Errors
|
CVE-2011-4079
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295007
|
- |
|
puppetlabs puppet
|
puppet puppet_enterprise_users puppet_enterprise
|
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to …
|
CWE-20
Improper Input Validation
|
CVE-2011-3872
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295008
|
- |
|
puppetlabs puppet
|
puppet
|
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-3871
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295009
|
- |
|
puppetlabs puppet
|
puppet
|
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
|
CWE-59
Link Following
|
CVE-2011-3870
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295010
|
- |
|
puppetlabs puppet
|
puppet
|
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
|
CWE-59
Link Following
|
CVE-2011-3869
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|