|
292821
|
- |
|
moodle
|
moodle
|
The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3388
|
2024-11-21 10:40 |
2012-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292822
|
- |
|
moodle
|
moodle
|
Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrict…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3387
|
2024-11-21 10:40 |
2012-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292823
|
- |
|
symantec
|
web_gateway
|
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-2977
|
2024-11-21 10:40 |
2012-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292824
|
- |
|
symantec
|
web_gateway
|
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to application scripts, related to an "injection" is…
|
CWE-78
OS Command
|
CVE-2012-2976
|
2024-11-21 10:40 |
2012-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292825
|
- |
|
symantec
|
web_gateway
|
SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2012-2961
|
2024-11-21 10:40 |
2012-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292826
|
- |
|
symantec
|
web_gateway
|
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-2957
|
2024-11-21 10:40 |
2012-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292827
|
- |
|
symantec
|
web_gateway
|
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.
|
CWE-78
OS Command
|
CVE-2012-2953
|
2024-11-21 10:40 |
2012-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292828
|
- |
|
wordpress
|
wordpress
|
WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vecto…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3385
|
2024-11-21 10:40 |
2012-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292829
|
- |
|
wordpress
|
wordpress
|
Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
|
CWE-352
Origin Validation Error
|
CVE-2012-3384
|
2024-11-21 10:40 |
2012-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292830
|
- |
|
wordpress
|
wordpress
|
The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3383
|
2024-11-21 10:40 |
2012-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|