|
291441
|
- |
|
joomla
|
joomla\!
|
Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language Switcher module for Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4532
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291442
|
- |
|
joomla
|
joomla\!
|
Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-4531
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291443
|
- |
|
nancy_wichmann
|
announcements
|
The Announcements module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the "access announcements" permission to bypass node access restrictions and possibly have other unsp…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4500
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291444
|
- |
|
matthias_hutterer
|
email
|
The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to email the stored address in the entity via unspecified vec…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4499
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291445
|
- |
|
inclind
|
custom_pub
|
Cross-site scripting (XSS) vulnerability in the Custom Publishing Options module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer nodes" permission to inject a…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4496
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291446
|
- |
|
mime_mail_module_project
|
mimemail
|
The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary f…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4495
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291447
|
- |
|
niif
|
shibb_auth
|
The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access restrictions and possibl…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4494
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291448
|
- |
|
isaac_sukin
|
shorten
|
Multiple cross-site scripting (XSS) vulnerabilities in the Shorten URLs module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions …
|
CWE-79
Cross-site Scripting
|
CVE-2012-4492
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291449
|
- |
|
tomatocart
|
tomatocart
|
TomatoCart 1.1.7, when the PayPal Express Checkout module is enabled in sandbox mode, allows remote authenticated users to bypass intended payment requirements by modifying a certain redirection URL.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4934
|
2024-11-21 10:43 |
2012-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291450
|
- |
|
emc
|
avamar
|
EMC Avamar Client for VMware 6.1 stores the cleartext server root password on the proxy client, which might allow remote attackers to obtain sensitive information by leveraging "network access" to th…
|
CWE-255
Credentials Management
|
CVE-2012-4610
|
2024-11-21 10:43 |
2012-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|