|
293491
|
- |
|
oscmax
|
oscmax
|
Multiple SQL injection vulnerabilities in the admin panel in osCMax before 2.5.1 allow (1) remote attackers to execute arbitrary SQL commands via the username parameter in a process action to admin/l…
|
CWE-89
SQL Injection
|
CVE-2012-1665
|
2024-11-21 10:37 |
2015-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293492
|
- |
|
oscmax
|
oscmax
|
Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in a process…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1664
|
2024-11-21 10:37 |
2015-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293493
|
- |
|
phpmoneybooks
|
phpmoneybooks
|
Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.
|
CWE-22
Path Traversal
|
CVE-2012-1669
|
2024-11-21 10:37 |
2014-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293494
|
- |
|
orangehrm
|
orangehrm
|
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plugins/ajaxCalls/haltR…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1507
|
2024-11-21 10:37 |
2014-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293495
|
- |
|
orangehrm
|
orangehrm
|
SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryI…
|
CWE-89
SQL Injection
|
CVE-2012-1506
|
2024-11-21 10:37 |
2014-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293496
|
- |
|
synology
|
diskstation_manager synology_photo_station
|
Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to ph…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1556
|
2024-11-21 10:37 |
2014-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293497
|
- |
|
sixapart
|
movable_type
|
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1503
|
2024-11-21 10:37 |
2014-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293498
|
- |
|
apache
|
ofbiz
|
Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.02 allow remote attackers to inject arbitrary web script or HTML via (1) a par…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1621
|
2024-11-21 10:37 |
2014-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293499
|
- |
|
phppgadmin_project opensuse
|
phppgadmin opensuse
|
Multiple cross-site scripting (XSS) vulnerabilities in functions.php in phpPgAdmin before 5.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) type of a functio…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1600
|
2024-11-21 10:37 |
2014-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293500
|
- |
|
danielb
|
finder
|
Cross-site scripting (XSS) vulnerability in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2012-1561
|
2024-11-21 10:37 |
2014-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|