|
292001
|
- |
|
c4b
|
xphone_unified_communications_2011
|
Cross-site scripting (XSS) vulnerability in the contacts in (1) XPhone UC Web and the (2) web frontend for XPhone Virtual Directory in C4B XPhone Unified Communications (UC) 2011 Web 4.1.890S R1 allo…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4259
|
2024-11-21 10:42 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292002
|
- |
|
myrephp
|
myre_real_estate_software
|
Multiple SQL injection vulnerabilities in MYRE Real Estate Software (2012 Q2) allow remote attackers to execute arbitrary SQL commands via the (1) link_idd parameter to 1_mobile/listings.php or (2) u…
|
CWE-89
SQL Injection
|
CVE-2012-4258
|
2024-11-21 10:42 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292003
|
- |
|
george_karpouzas
|
yet_another_question_\&_answer_system
|
Yaqas (Yet Another Question & Answer System) 1.0 Alpha 1 allows remote attackers to obtain sensitive information via an invalid character in the PHPSESSID, which reveals the installation path in an e…
|
CWE-200
Information Exposure
|
CVE-2012-4257
|
2024-11-21 10:42 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292004
|
- |
|
joobi
|
com_jnews
|
The jNews (com_jnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2012-4256
|
2024-11-21 10:42 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292005
|
- |
|
mysqldumper
|
mysqldumper
|
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information via a direct request to learn/cubemail/refresh_dblist.php, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2012-4255
|
2024-11-21 10:42 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292006
|
- |
|
mysqldumper
|
mysqldumper
|
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/cubemail/restore.php or (2) learn/cubemail/dump.php.
|
CWE-200
Information Exposure
|
CVE-2012-4254
|
2024-11-21 10:42 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292007
|
- |
|
mysqldumper
|
mysqldumper
|
Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to learn/cubemail/install.php or (2)…
|
CWE-22
Path Traversal
|
CVE-2012-4253
|
2024-11-21 10:42 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292008
|
- |
|
mysqldumper
|
mysqldumper
|
Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of administrators for requests that (1) remove file access restric…
|
CWE-352
Origin Validation Error
|
CVE-2012-4252
|
2024-11-21 10:42 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292009
|
- |
|
mysqldumper
|
mysqldumper
|
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4251
|
2024-11-21 10:42 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292010
|
- |
|
samsung
|
net-i_viewer
|
Stack-based buffer overflow in the RequestScreenOptimization function in the XProcessControl.ocx ActiveX control in msls31.dll in Samsung NET-i viewer 1.37 allows remote attackers to execute arbitrar…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-4250
|
2024-11-21 10:42 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|