|
289811
|
- |
|
mutiny
|
mutiny_appliance mutiny_virtual_appliance mutiny
|
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbi…
|
CWE-22
Path Traversal
|
CVE-2013-0136
|
2024-11-21 10:46 |
2013-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289812
|
- |
|
cisco
|
webex
|
Cisco WebEx 4.1 on iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middl…
|
CWE-20
Improper Input Validation
|
CVE-2012-6399
|
2024-11-21 10:46 |
2013-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289813
|
- |
|
elgg
|
elgg
|
engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6563
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289814
|
- |
|
elgg
|
elgg
|
engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to create arbitrary accounts.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6562
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289815
|
- |
|
elgg
|
elgg
|
Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the view parameter to index.php. NOTE: some o…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6561
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289816
|
- |
|
freenac
|
freenac
|
SQL injection vulnerability in deviceadd.php in FreeNAC 3.02 allows remote attackers to execute arbitrary SQL commands via the status parameter.
|
CWE-20
Improper Input Validation
|
CVE-2012-6560
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289817
|
- |
|
freenac
|
freenac
|
Multiple cross-site scripting (XSS) vulnerabilities in FreeNAC 3.02 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) mac, (3) graphtype, (4) name, or (5) type pa…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6559
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289818
|
- |
|
heaventools
|
pe_explorer
|
Heap-based buffer overflow in HeavenTools PE Explorer 1.99 R6 allows remote attackers to execute arbitrary code via the size value for a string in the resource section of a Portable Executable (PE) f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-6558
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289819
|
- |
|
zodiacdm
|
aboutme-plugin
|
Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web script or HTML via the (1) AboutMe/RealName, (2) Abou…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6557
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289820
|
- |
|
jspautsch
|
firstlastnames
|
Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web script or HTML via the (1) User/FirstName or (…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6556
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|