|
291121
|
- |
|
gecad
|
axigen_free_mail_server
|
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in (1) the fileName…
|
CWE-22
Path Traversal
|
CVE-2012-4940
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291122
|
- |
|
solarwinds
|
orion_network_performance_monitor ip_address_manager_web_interface
|
Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject ar…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4939
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291123
|
- |
|
xen
|
xen
|
The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of se…
|
CWE-20
Improper Input Validation
|
CVE-2012-4544
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291124
|
- |
|
joomla
|
joomla\!
|
Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language Switcher module for Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4532
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291125
|
- |
|
joomla
|
joomla\!
|
Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-4531
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291126
|
- |
|
nancy_wichmann
|
announcements
|
The Announcements module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the "access announcements" permission to bypass node access restrictions and possibly have other unsp…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4500
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291127
|
- |
|
matthias_hutterer
|
email
|
The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to email the stored address in the entity via unspecified vec…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4499
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291128
|
- |
|
inclind
|
custom_pub
|
Cross-site scripting (XSS) vulnerability in the Custom Publishing Options module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer nodes" permission to inject a…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4496
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291129
|
- |
|
mime_mail_module_project
|
mimemail
|
The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary f…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4495
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291130
|
- |
|
niif
|
shibb_auth
|
The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access restrictions and possibl…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4494
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|