|
289641
|
5.4 |
MEDIUM
Network
|
havalite
|
havalite
|
Havalite CMS 1.1.7 has a stored XSS vulnerability
|
CWE-79
Cross-site Scripting
|
CVE-2013-0161
|
2024-11-21 10:46 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289642
|
8.8 |
HIGH
Network
|
polycom
|
hdx_video_end_points uc_apl
|
Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping command feature.
|
CWE-78
OS Command
|
CVE-2012-6610
|
2024-11-21 10:46 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289643
|
7.5 |
HIGH
Network
|
polycom
|
hdx_video_end_points uc_apl
|
Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name…
|
CWE-22
Path Traversal
|
CVE-2012-6609
|
2024-11-21 10:46 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289644
|
6.1 |
MEDIUM
Network
|
cpanel
|
webhost_manager
|
Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6448
|
2024-11-21 10:46 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289645
|
7.2 |
HIGH
Network
|
dlink
|
dsr-250n_firmware
|
D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.
|
NVD-CWE-noinfo
|
CVE-2012-6613
|
2024-11-21 10:46 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289646
|
6.1 |
MEDIUM
Network
|
rapid7
|
nexpose
|
Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorized access.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6494
|
2024-11-21 10:46 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289647
|
7.5 |
HIGH
Network
|
novell
|
zenworks_configuration_management
|
Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.
|
NVD-CWE-noinfo
|
CVE-2012-6345
|
2024-11-21 10:46 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289648
|
6.1 |
MEDIUM
Network
|
novell
|
zenworks_configuration_management
|
Novell ZENworks Configuration Management before 11.2.4 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6344
|
2024-11-21 10:46 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289649
|
9.8 |
CRITICAL
Network
|
lorextechnology
|
lnc116_firmware lnc104_firmware
|
Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability
|
CWE-287
Improper Authentication
|
CVE-2012-6451
|
2024-11-21 10:46 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289650
|
7.5 |
HIGH
Network
|
ge
|
d20me_firmware d200_firmware
|
General Electric D20ME devices are not properly configured and reveal plaintext passwords.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2012-6663
|
2024-11-21 10:46 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|