Search Results (89519 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2012-6494 1 Rapid7 1 Nexpose 2024-11-21 6.1 Medium
Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorized access.
CVE-2012-6449 1 Cpanel 2 Cpanel, Whm 2024-11-21 5.4 Medium
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
CVE-2012-6448 1 Cpanel 1 Webhost Manager 2024-11-21 6.1 Medium
Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2012-6347 1 Fortinet 1 Fortidb 2024-11-21 N/A
Multiple cross-site scripting (XSS) vulnerabilities in Java number format exception handling in FortiGate FortiDB before 4.4.2 allow remote attackers to inject arbitrary web script or HTML via the conversationContext parameter to (1) admin/auditTrail.jsf, (2) mapolicymgmt/targetsMonitorView.jsf, (3) vascan/globalsummary.jsf, (4) vaerrorlog/vaErrorLog.jsf, (5) database/listTargetGroups.jsf, (6) sysconfig/listSystemInfo.jsf, (7) vascan/list.jsf, (8) network/router.jsf, (9) mapolicymgmt/editPolicyProfile.jsf, or (10) mapolicymgmt/maPolicyMasterList.jsf.
CVE-2012-6346 1 Fortinet 1 Fortiweb 2024-11-21 N/A
Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) redir or (2) mkey parameter to waf/pcre_expression/validate.
CVE-2012-6344 1 Novell 1 Zenworks Configuration Management 2024-11-21 6.1 Medium
Novell ZENworks Configuration Management before 11.2.4 allows XSS.
CVE-2012-6133 1 Roundup-tracker 1 Roundup 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*.
CVE-2012-5878 1 Bulbsecurity 1 Smartphone Pentest Framework 2024-11-21 9.8 Critical
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl.
CVE-2012-5867 1 Ht Editor Project 1 Ht Editor 2024-11-21 9.8 Critical
HT Editor 2.0.20 has a Remote Stack Buffer Overflow Vulnerability
CVE-2012-5776 1 Dokeos 1 Dokeos 2024-11-21 5.4 Medium
Dokeos 2.1.1 has multiple XSS issues involving "extra_" parameters in main/auth/profile.php.
CVE-2012-5693 1 Bulbsecurity 1 Smartphone Pentest Framework 2024-11-21 8.8 High
Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddressTB parameter to (1) remoteAttack.pl or (2) guessPassword.pl in frameworkgui/; the filename parameter to (3) CSAttack.pl or (4) SEAttack.pl in frameworkgui/; the phNo2Attack parameter to (5) CSAttack.pl or (6) SEAttack.pl in frameworkgui/; the (7) platformDD2 parameter to frameworkgui/SEAttack.pl; the (8) agentURLPath or (9) agentControlKey parameter to frameworkgui/attach2agents.pl; or the (10) controlKey parameter to frameworkgui/attachMobileModem.pl. NOTE: The hostingPath parameter to CSAttack.pl and SEAttack.pl vectors and the appURLPath parameter to attachMobileModem.pl vector are covered by CVE-2012-5878.
CVE-2012-5686 1 Zpanelcp 1 Zpanel 2024-11-21 9.8 Critical
ZPanel 10.0.1 has insufficient entropy for its password reset process.
CVE-2012-5558 2 Smiley Project, Smileys Project 2 Smiley, Smileys 2024-11-21 4.8 Medium
Cross-site scripting (XSS) vulnerability in the Smiley module 6.x-1.x versions prior to 6.x-1.1 and Smileys module 6.x-1.x versions prior to 6.x-1.1 for Drupal allows remote authenticated users with the "administer smiley" permission to inject arbitrary web script or HTML via a smiley acronym.
CVE-2012-5193 1 Bitweaver 1 Bitweaver 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsletters/edition.php or the (3) username parameter to users/remind_password.php, (4) days parameter to stats/index.php, (5) login parameter to users/register.php, or (6) highlight parameter.
CVE-2012-4981 1 Toshiba 1 Configfree 2024-11-21 8.8 High
Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability
CVE-2012-4980 1 Toshiba 1 Configfree Utility 2024-11-21 7.8 High
Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.
CVE-2012-4900 1 Corel 1 Wordperfect Office X6 2024-11-21 5.5 Medium
Corel WordPerfect Office X6 16.0.0.388 has a DoS Vulnerability via untrusted pointer dereference
CVE-2012-4526 1 Piwigo 1 Piwigo 2024-11-21 6.1 Medium
piwigo has XSS in password.php (incomplete fix for CVE-2012-4525)
CVE-2012-4525 1 Piwigo 1 Piwigo 2024-11-21 6.1 Medium
piwigo has XSS in password.php
CVE-2012-4519 1 Zenphoto 1 Zenphoto 2024-11-21 6.1 Medium
Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.