|
288601
|
- |
|
rapid7
|
nexpose
|
Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers to hijack the authentication of unspecified victims for requests that delete sc…
|
CWE-352
Origin Validation Error
|
CVE-2012-6493
|
2024-11-21 10:46 |
2014-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288602
|
- |
|
splunk
|
splunk
|
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk 5.0.0 through 5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6447
|
2024-11-21 10:46 |
2014-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288603
|
- |
|
kernel
|
util-linux
|
(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line …
|
CWE-200
Information Exposure
|
CVE-2013-0157
|
2024-11-21 10:46 |
2014-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288604
|
- |
|
wordpress
|
wordpress
|
wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by vi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6635
|
2024-11-21 10:46 |
2014-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288605
|
- |
|
wordpress
|
wordpress
|
wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6634
|
2024-11-21 10:46 |
2014-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288606
|
- |
|
wordpress
|
wordpress
|
Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6633
|
2024-11-21 10:46 |
2014-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288607
|
- |
|
vessio
|
netbill
|
Multiple cross-site scripting (XSS) vulnerabilities in Vessio NetBill 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) file title to accounts/admin/index…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6632
|
2024-11-21 10:46 |
2014-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288608
|
- |
|
vessio
|
netbill
|
Cross-site request forgery (CSRF) vulnerability in accounts/admin/index.php in Vessio NetBill 1.2 allows remote attackers to hijack the authentication of administrators for requests that add accounts…
|
CWE-352
Origin Validation Error
|
CVE-2012-6631
|
2024-11-21 10:46 |
2014-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288609
|
- |
|
rick_mead
|
media_library_categories
|
Multiple cross-site scripting (XSS) vulnerabilities in the Media Library Categories plugin 1.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) bulk parameter…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6630
|
2024-11-21 10:46 |
2014-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288610
|
- |
|
xyzscripts
|
newsletter_manager
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for r…
|
CWE-352
Origin Validation Error
|
CVE-2012-6629
|
2024-11-21 10:46 |
2014-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|