|
290841
|
- |
|
directadmin
|
directadmin
|
Cross-site scripting (XSS) vulnerability in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allows remote attackers to inject arbitrary web script or HTML via the domain parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-5305
|
2024-11-21 10:44 |
2012-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290842
|
- |
|
yuriy_v_semenikhin
|
yvs_image_gallery
|
Static code injection vulnerability in administration/install.php in YVS Image Gallery allows remote attackers to inject arbitrary PHP code into functions/db_connect.php via unspecified vectors. NOT…
|
CWE-94
Code Injection
|
CVE-2012-5304
|
2024-11-21 10:44 |
2012-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290843
|
- |
|
monkey-project
|
monkey
|
Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname different from the default /var/run/monkey.pid pathname.
|
CWE-59
Link Following
|
CVE-2012-5303
|
2024-11-21 10:44 |
2012-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290844
|
- |
|
cerberusftp
|
ftp_server
|
The default configuration of Cerberus FTP Server before 5.0.4.0 supports the DES cipher for SSH sessions, which makes it easier for remote attackers to obtain sensitive information by sniffing the ne…
|
CWE-310
Cryptographic Issues
|
CVE-2012-5301
|
2024-11-21 10:44 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290845
|
- |
|
wireshark
|
wireshark
|
Buffer overflow in the dissect_tlv function in epan/dissectors/packet-ldp.c in the LDP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (application cras…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-5240
|
2024-11-21 10:44 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290846
|
- |
|
wireshark
|
wireshark
|
epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.3 uses incorrect OUI data structures during the decoding of (1) PPP and (2) LCP data, which allows remote attackers to …
|
NVD-CWE-noinfo
|
CVE-2012-5238
|
2024-11-21 10:44 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290847
|
- |
|
wireshark
|
wireshark
|
The dissect_hsrp function in epan/dissectors/packet-hsrp.c in the HSRP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed p…
|
CWE-399
Resource Management Errors
|
CVE-2012-5237
|
2024-11-21 10:44 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290848
|
- |
|
mystorexpress
|
tienda_virtual
|
SQL injection vulnerability in art_catalogo.php in MyStore Xpress Tienda Virtual 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2012-5300
|
2024-11-21 10:44 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290849
|
- |
|
mavili_guestbook_project
|
mavili_guestbook
|
Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) edit.asp, (2) delete.asp, or (3) approve.asp.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5299
|
2024-11-21 10:44 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290850
|
- |
|
mavili_guestbook_project
|
mavili_guestbook
|
Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attackers to read the database via a direct request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5298
|
2024-11-21 10:44 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|