|
291841
|
7.5 |
HIGH
Network
|
cakefoundation
|
cakephp
|
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE)…
|
CWE-611
XXE
|
CVE-2012-4399
|
2024-11-21 10:42 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291842
|
- |
|
glpi-project
|
glpi
|
Multiple cross-site scripting (XSS) vulnerabilities in GLPI-PROJECT GLPI before 0.83.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-4003
|
2024-11-21 10:42 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291843
|
- |
|
glpi-project
|
glpi
|
Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI before 0.83.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
|
CWE-352
Origin Validation Error
|
CVE-2012-4002
|
2024-11-21 10:42 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291844
|
- |
|
oracle
|
mysql
|
MySQL 5.0.88, and possibly other versions and platforms, allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4452
|
2024-11-21 10:42 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291845
|
- |
|
openstack
|
keystone
|
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's …
|
CWE-287
Improper Authentication
|
CVE-2012-4457
|
2024-11-21 10:42 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291846
|
- |
|
openstack
|
keystone
|
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the ro…
|
CWE-287
Improper Authentication
|
CVE-2012-4456
|
2024-11-21 10:42 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291847
|
- |
|
monkey-project
|
monkey
|
Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictio…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4442
|
2024-11-21 10:42 |
2012-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291848
|
- |
|
monkey-project
|
monkey
|
Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gain privileges by leveraging cgi-bin write access.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4443
|
2024-11-21 10:42 |
2012-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291849
|
- |
|
finalbeta
|
mywebsearch
|
Cross-site scripting (XSS) vulnerability in Final Beta Laboratory MyWebSearch before 1.23 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-4018
|
2024-11-21 10:42 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291850
|
- |
|
mf_gig_calendar_project
|
mf_gig_calendar
|
Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar page.
|
CWE-79
Cross-site Scripting
|
CVE-2012-4242
|
2024-11-21 10:42 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|