|
290041
|
6.1 |
MEDIUM
Network
|
roundup-tracker
|
roundup
|
Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to i…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6133
|
2024-11-21 10:45 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290042
|
5.4 |
MEDIUM
Network
|
dokeos
|
dokeos
|
Dokeos 2.1.1 has multiple XSS issues involving "extra_" parameters in main/auth/profile.php.
|
CWE-79
Cross-site Scripting
|
CVE-2012-5776
|
2024-11-21 10:45 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290043
|
5.5 |
MEDIUM
Local
|
git-extras_project
|
git-extras
|
The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort.
|
CWE-59
Link Following
|
CVE-2012-6114
|
2024-11-21 10:45 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290044
|
7.8 |
HIGH
Local
|
soapbox_project
|
soapbox
|
Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox.
|
CWE-269
Improper Privilege Management
|
CVE-2012-6302
|
2024-11-21 10:45 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290045
|
7.5 |
HIGH
Network
|
freeciv
|
freeciv
|
Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2012-6083
|
2024-11-21 10:45 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290046
|
9.8 |
CRITICAL
Network
|
ht_editor_project
|
ht_editor
|
HT Editor 2.0.20 has a Remote Stack Buffer Overflow Vulnerability
|
CWE-787
Out-of-bounds Write
|
CVE-2012-5867
|
2024-11-21 10:45 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290047
|
9.8 |
CRITICAL
Network
|
babygekko
|
babygekko
|
BabyGekko before 1.2.4 allows PHP file inclusion.
|
CWE-20
Improper Input Validation
|
CVE-2012-5699
|
2024-11-21 10:45 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290048
|
8.8 |
HIGH
Network
|
babygekko
|
babygekko
|
BabyGekko before 1.2.4 has SQL injection.
|
CWE-89
SQL Injection
|
CVE-2012-5698
|
2024-11-21 10:45 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290049
|
9.8 |
CRITICAL
Network
|
bulbsecurity
|
smartphone_pentest_framework
|
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or …
|
CWE-78
OS Command
|
CVE-2012-5878
|
2024-11-21 10:45 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290050
|
8.8 |
HIGH
Adjacent
|
bulbsecurity
|
smartphone_pentest_framework
|
Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddressTB parameter to (1) remoteAttack.pl or (2)…
|
CWE-78
OS Command
|
CVE-2012-5693
|
2024-11-21 10:45 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|