|
289981
|
7.8 |
HIGH
Local
|
gnu redhat
|
bash enterprise_linux
|
A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through the echo built-in fu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-6711
|
2024-11-21 10:46 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289982
|
9.8 |
CRITICAL
Network
|
page_flip_book_project
|
page_flip_book
|
Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppageflip) allows remote attackers to include and execute arbitrary local files vi…
|
CWE-22
Path Traversal
|
CVE-2012-6652
|
2024-11-21 10:46 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289983
|
9.8 |
CRITICAL
Network
|
extplorer
|
extplorer
|
ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php.
|
CWE-287
Improper Authentication
|
CVE-2012-6710
|
2024-11-21 10:46 |
2018-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289984
|
7.1 |
HIGH
Local
|
fedoraproject
|
fedora
|
The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial of service or write to arbitrary files via a symli…
|
CWE-59
Link Following
|
CVE-2013-0159
|
2024-11-21 10:46 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289985
|
5.9 |
MEDIUM
Network
|
elinks twibright
|
elinks links
|
ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2012-6709
|
2024-11-21 10:46 |
2018-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289986
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortidb
|
Multiple cross-site scripting (XSS) vulnerabilities in Java number format exception handling in FortiGate FortiDB before 4.4.2 allow remote attackers to inject arbitrary web script or HTML via the co…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6347
|
2024-11-21 10:46 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289987
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortiweb
|
Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) redir or (2) mkey parameter to waf/pcre_expressi…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6346
|
2024-11-21 10:46 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289988
|
6.1 |
MEDIUM
Network
|
jquery
|
jquery
|
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6708
|
2024-11-21 10:46 |
2018-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289989
|
6.1 |
MEDIUM
Network
|
dragonbyte-tech
|
vbdownloads_module
|
Cross-site scripting (XSS) vulnerability in downloads/actions/editdownload.php in the DragonByte Technologies vBDownloads module 1.3.2 and earlier for vBulletin allows remote attackers to inject arbi…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6682
|
2024-11-21 10:46 |
2018-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289990
|
6.1 |
MEDIUM
Network
|
dragonbyte-tech
|
forumon_rpg_module
|
Multiple cross-site scripting (XSS) vulnerabilities in actions/main.php in the DragonByte Technologies Forumon RPG module before 1.0.8 for vBulletin when creating a new monster, allow remote attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6671
|
2024-11-21 10:46 |
2018-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|