|
291201
|
- |
|
luizpicanco
|
hserver
|
Directory traversal vulnerability in HServer 0.1.1 allows remote attackers to read arbitrary files via a (1) ..%5c (dot dot encoded backslash) or (2) %2e%2e%5c (encoded dot dot backslash) in the PATH…
|
CWE-22
Path Traversal
|
CVE-2012-5100
|
2024-11-21 10:44 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291202
|
- |
|
phpb2b
|
phpb2b
|
Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.
|
CWE-79
Cross-site Scripting
|
CVE-2012-5099
|
2024-11-21 10:44 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291203
|
- |
|
j_waite
|
php-x-links
|
Multiple SQL injection vulnerabilities in Php-X-Links, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to rate.php, (2) cid parameter to view.php, or (…
|
CWE-89
SQL Injection
|
CVE-2012-5098
|
2024-11-21 10:44 |
2012-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291204
|
6.5 |
MEDIUM
Network
|
ibm
|
infosphere_information_server
|
IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to obtain sensitive information, caused by improper restrictions on directories. An attacker could expl…
|
NVD-CWE-noinfo
|
CVE-2012-4818
|
2024-11-21 10:43 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291205
|
6.1 |
MEDIUM
Network
|
zenphoto
|
zenphoto
|
Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2012-4519
|
2024-11-21 10:43 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291206
|
8.8 |
HIGH
Network
|
kde redhat
|
kde enterprise_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server_eus
|
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "ty…
|
CWE-843
Type Confusion
|
CVE-2012-4512
|
2024-11-21 10:43 |
2020-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291207
|
7.8 |
HIGH
Local
|
citrix
|
xenserver
|
Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with acc…
|
CWE-269
Improper Privilege Management
|
CVE-2012-4606
|
2024-11-21 10:43 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291208
|
8.8 |
HIGH
Network
|
toshiba
|
configfree
|
Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability
|
CWE-78
OS Command
|
CVE-2012-4981
|
2024-11-21 10:43 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291209
|
5.5 |
MEDIUM
Local
|
corel
|
wordperfect_office_x6
|
Corel WordPerfect Office X6 16.0.0.388 has a DoS Vulnerability via untrusted pointer dereference
|
CWE-787
Out-of-bounds Write
|
CVE-2012-4900
|
2024-11-21 10:43 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291210
|
6.5 |
MEDIUM
Network
|
ibm
|
websphere_mq
|
IBM WebSphere MQ 7.1 and 7.5: Queue manager has a DoS vulnerability
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2012-4863
|
2024-11-21 10:43 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|