|
294611
|
- |
|
phux
|
download_manager
|
SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via the file parameter.
|
CWE-89
SQL Injection
|
CVE-2012-0980
|
2024-11-21 10:36 |
2012-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294612
|
- |
|
twiki
|
twiki
|
Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field in a profile, involving (1) registration or (2) editing of …
|
CWE-79
Cross-site Scripting
|
CVE-2012-0979
|
2024-11-21 10:36 |
2012-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294613
|
- |
|
luratech
|
lurawave_jp2_browser_plug-in
|
Stack-based buffer overflow in npjp2.dll in LuraWave JP2 Browser Plug-In 1.1.1.11 and other versions before 2.1.1.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-0978
|
2024-11-21 10:36 |
2012-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294614
|
- |
|
luratech
|
lurawave_jp2_activex_control
|
Stack-based buffer overflow in jp2_x.dll in LuraWave JP2 ActiveX Control 2.1.5.5 and other versions before 2.1.5.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-0977
|
2024-11-21 10:36 |
2012-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294615
|
- |
|
silverstripe
|
silverstripe
|
Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title…
|
CWE-79
Cross-site Scripting
|
CVE-2012-0976
|
2024-11-21 10:36 |
2012-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294616
|
- |
|
clixint
|
image_hosting_script_dpi
|
Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-0975
|
2024-11-21 10:36 |
2012-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294617
|
- |
|
wordpress
|
wordpress
|
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which allows remote attacker…
|
NVD-CWE-noinfo
|
CVE-2012-0937
|
2024-11-21 10:36 |
2012-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294618
|
- |
|
opennms.org
|
opennms
|
Cross-site scripting (XSS) vulnerability in web/springframework/security/SecurityAuthenticationEventOnmsEventBuilder.java in OpenNMS 1.8.x before 1.8.17, 1.9.93 and earlier, and 1.10.x before 1.10.1 …
|
CWE-79
Cross-site Scripting
|
CVE-2012-0936
|
2024-11-21 10:36 |
2012-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294619
|
- |
|
aryadad
|
aryadad_cms
|
SQL injection vulnerability in Default.aspx in Aryadad CMS allows remote attackers to execute arbitrary SQL commands via the PageID parameter.
|
CWE-89
SQL Injection
|
CVE-2012-0935
|
2024-11-21 10:36 |
2012-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294620
|
- |
|
zingiri
|
theme_tuner_plugin
|
PHP remote file inclusion vulnerability in ajax/savetag.php in the Theme Tuner plugin for WordPress before 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the tt-abspath parame…
|
CWE-94
Code Injection
|
CVE-2012-0934
|
2024-11-21 10:36 |
2012-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|