CVE-2012-4000 to CVE-2012-4999
159 CVEs with public proof-of-concept exploits.
- CVE-2012-40001 PoCCross-site scripting (XSS) vulnerability in the print_textinputs_var function in…
- CVE-2012-40291 PoCCross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject…
- CVE-2012-40313 PoCsMultiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attackers to read…
- CVE-2012-40322 PoCsOpen redirect vulnerability in the login page in WebsitePanel before 1.2.2.1 allows remote attackers to redirect users to arbitrary web…
- CVE-2012-40341 PoCMultiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the (1) username…
- CVE-2012-40351 PoCThe new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and…
- CVE-2012-40361 PoCUnrestricted file upload vulnerability in admin.php in PBBoard 2.1.4 allows remote administrators to execute arbitrary PHP code by…
- CVE-2012-40511 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper…
- CVE-2012-40542 PoCsBuffer overflow in the readfile function in CPE17 Autorun Killer 1.7.1 and earlier allows physically proximate attackers to execute…
- CVE-2012-40551 PoCSQL injection vulnerability in index2.php in Uiga Fan Club allows remote attackers to execute arbitrary SQL commands via the p parameter.
- CVE-2012-40572 PoCsBuffer overflow in the Player in Remote-Anything 5.60.15 allows remote attackers to execute arbitrary code via a crafted flm file.
- CVE-2012-40601 PoCMultiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands via the id…
- CVE-2012-40701 PoCSQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2012-41701 PoCBuffer overflow in Adobe Photoshop CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafted file.
- CVE-2012-41774 PoCsThe web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path…
- CVE-2012-41782 PoCsSQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute…
- CVE-2012-41891 PoCCross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote…
- CVE-2012-41941 PoCMozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and…
- CVE-2012-42202 PoCsdiagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows…
- CVE-2012-42252 PoCsNVIDIA UNIX graphics driver before 295.71 and before 304.32 allows local users to write to arbitrary physical memory locations and gain…
- CVE-2012-42311 PoCCross-site scripting (XSS) vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to inject arbitrary web script…
- CVE-2012-42341 PoCCross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum before 5.2.19 allows…
- CVE-2012-42361 PoCCross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK…
- CVE-2012-42372 PoCsMultiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to…
- CVE-2012-42402 PoCsSQL injection vulnerability in modules/calendar/json.php in Group-Office community before 4.0.90 allows remote authenticated users to…
- CVE-2012-42422 PoCsCross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web…
- CVE-2012-42461 PoCMultiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject…
- CVE-2012-42471 PoCMultiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject…
- CVE-2012-42502 PoCsStack-based buffer overflow in the RequestScreenOptimization function in the XProcessControl.ocx ActiveX control in msls31.dll in Samsung…
- CVE-2012-42514 PoCsMultiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2012-42521 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of…
- CVE-2012-42533 PoCsMultiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in…
- CVE-2012-42541 PoCMySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1)…
- CVE-2012-42583 PoCsMultiple SQL injection vulnerabilities in MYRE Real Estate Software (2012 Q2) allow remote attackers to execute arbitrary SQL commands via…
- CVE-2012-42592 PoCsCross-site scripting (XSS) vulnerability in the contacts in (1) XPhone UC Web and the (2) web frontend for XPhone Virtual Directory in C4B…
- CVE-2012-42602 PoCsMultiple SQL injection vulnerabilities in myCare2x allow remote attackers to execute arbitrary SQL commands via the (1) aktion or (2)…
- CVE-2012-42611 PoCSQL injection vulnerability in modules/patient/mycare2x_pat_info.php in myCare2x allows remote attackers to execute arbitrary SQL commands…
- CVE-2012-42622 PoCsMultiple cross-site scripting (XSS) vulnerabilities in myCare2x allow remote attackers to inject arbitrary web script or HTML via the (1)…
- CVE-2012-42652 PoCsSQL injection vulnerability in category_edit.php in Proman Xpress 5.0.1 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2012-42662 PoCsCross-site scripting (XSS) vulnerability in client_details.php in Proman Xpress 5.0.1 allows remote attackers to inject arbitrary web…
- CVE-2012-42672 PoCsCross-site scripting (XSS) vulnerability in user/register in Sockso 1.5 and earlier allows remote attackers to inject arbitrary web script…
- CVE-2012-42731 PoCCross-site scripting (XSS) vulnerability in libs/xing.php in the 2 Click Social Media Buttons plugin before 0.34 for WordPress allows…
- CVE-2012-42782 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2012-42792 PoCsMultiple SQL injection vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to execute arbitrary SQL commands via the (1) view…
- CVE-2012-42802 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in admin/agenteditor.php in Free Realty 3.1-0.6 allow remote attackers to…
- CVE-2012-42812 PoCsMultiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid…
- CVE-2012-42821 PoCSQL injection vulnerability in photo.php in Trombinoscope 3.5 allows remote attackers to execute arbitrary SQL commands via the id…
- CVE-2012-42845 PoCsA Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set…
- CVE-2012-43252 PoCsCross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and earlier allows remote attackers to…
- CVE-2012-43293 PoCsThe Samsung D6000 TV and possibly other products allow remote attackers to cause a denial of service (continuous restart) via a crafted…
- CVE-2012-43303 PoCsThe Samsung D6000 TV and possibly other products allows remote attackers to cause a denial of service (crash) via a long string in certain…
- CVE-2012-43334 PoCsMultiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls…
- CVE-2012-43342 PoCsThe ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316…
- CVE-2012-43352 PoCsSamsung NET-i viewer 1.37.120316 allows remote attackers to cause a denial of service (infinite loop) via a negative size value in a TCP…
- CVE-2012-43361 PoCMultiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to inject arbitrary web…
- CVE-2012-43442 PoCsCross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold 15.02 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2012-43472 PoCsMultiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote…
- CVE-2012-43531 PoCStack-based buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allows…
- CVE-2012-43541 PoCTCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allows remote attackers to execute…
- CVE-2012-43551 PoCTCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute…
- CVE-2012-43562 PoCsMultiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allow…
- CVE-2012-43571 PoCArray index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow remote attackers to…
- CVE-2012-43615 PoCslhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary…
- CVE-2012-43624 PoCshydra.exe in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance has a hardcoded password of L0CAlu53R for the global$agent account,…
- CVE-2012-43661 PoCBelkin wireless routers Surf N150 Model F7D1301v1, N900 Model F9K1104v1, N450 Model F9K1105V2, and N300 Model F7D2301v1 generate a…
- CVE-2012-43841 PoCletodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar
- CVE-2012-43852 PoCsletodms 3.3.6 has CSRF via change password
- CVE-2012-43993 PoCsThe Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing…
- CVE-2012-44093 PoCsStack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers…
- CVE-2012-44122 PoCsInteger overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to…
- CVE-2012-44151 PoCStack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause…
- CVE-2012-44211 PoCThe create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which…
- CVE-2012-44221 PoCwp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges…
- CVE-2012-44241 PoCStack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent…
- CVE-2012-44252 PoCslibgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges…
- CVE-2012-44311 PoCorg/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to…
- CVE-2012-45122 PoCsThe CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and…
- CVE-2012-45131 PoCkhtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read…
- CVE-2012-45141 PoCrendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer…
- CVE-2012-45151 PoCUse-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows…
- CVE-2012-45282 PoCsThe mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data…
- CVE-2012-45301 PoCThe load_script function in fs/binfmt_script.c in the Linux kernel before 3.7.2 does not properly handle recursion, which allows local…
- CVE-2012-45471 PoCUnspecified vulnerability in awredir.pl in AWStats before 7.1 has unknown impact and attack vectors.
- CVE-2012-45521 PoCStack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via…
- CVE-2012-45541 PoCThe OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an…
- CVE-2012-45983 PoCsAn unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to execute arbitrary…
- CVE-2012-46002 PoCsCross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and…
- CVE-2012-46681 PoCCross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitrary web script or…
- CVE-2012-46791 PoCCross-site scripting (XSS) vulnerability in admin/login.php in Newscoop before 3.5.5 allows remote attackers to inject arbitrary web…
- CVE-2012-46801 PoCDirectory traversal vulnerability in the XML Server in IOServer before 1.0.19.0, when the Root Directory pathname lacks a trailing \…
- CVE-2012-46815 PoCsKEVMultiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers…
- CVE-2012-46851 PoCCross-site scripting (XSS) vulnerability in Arbor Networks Peakflow SP 5.1.1 before patch 6, 5.5 before patch 4, and 5.6.0 before patch 1…
- CVE-2012-46861 PoCSQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2012-47052 PoCsDirectory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via…
- CVE-2012-47112 PoCsBuffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and…
- CVE-2012-47392 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Barracuda SSL VPN before 2.2.2.203 (2012-07-05) allow remote attackers to inject…
- CVE-2012-47451 PoCCross-site scripting (XSS) vulnerability in admin/login.asp in Acuity CMS 2.6.2 allows remote attackers to inject arbitrary web script or…
- CVE-2012-47463 PoCsCross-site request forgery (CSRF) vulnerability in accessaccount.cgi in ZTE ZXDSL 831IIV7.5.0a_Z29_OV allows remote attackers to hijack…
- CVE-2012-47501 PoCA Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a…
- CVE-2012-47512 PoCsCross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x before 3.0.17, and…
- CVE-2012-47591 PoCUntrusted search path vulnerability in facebook_plugin.fpi in the Facebook plug-in in Foxit Reader 5.3.1.0606 allows local users to gain…
- CVE-2012-47601 PoCA Privilege Escalation vulnerability exists in the SDBagent service in Safend Data Protector Agent 3.4.5586.9772, which could let a local…
- CVE-2012-47611 PoCA Privilege Escalation vulnerability exists in the unquoted Service Binary in SDPAgent or SDBAgent in Safend Data Protector Agent…
- CVE-2012-47671 PoCAn issue exists in Safend Data Protector Agent 3.4.5586.9772 in the securitylayer.log file in the logs.9972 directory, which could let a…
- CVE-2012-47682 PoCsCross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject…
- CVE-2012-47711 PoCMultiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or…
- CVE-2012-47721 PoCSQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2012-47732 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication…
- CVE-2012-47924 PoCsKEVUse-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted…
- CVE-2012-48642 PoCsOreans WinLicense 2.1.8.0 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute…
- CVE-2012-48652 PoCsBuffer overflow in Oreans Themida 2.1.8.0 allows remote attackers to execute arbitrary code via a crafted .TMD file.
- CVE-2012-48672 PoCsDirectory traversal vulnerability in modules/com_vtiger_workflow/sortfieldsjson.php in vtiger CRM 5.1.0 allows remote attackers to read…
- CVE-2012-48681 PoCSQL injection vulnerability in news.php in the Kunena component 1.7.2 for Joomla! allows remote attackers to execute arbitrary SQL…
- CVE-2012-48697 PoCsThe callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute…
- CVE-2012-48702 PoCsMultiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.9 and earlier allow remote attackers to inject arbitrary web script or…
- CVE-2012-48711 PoCCross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote…
- CVE-2012-48732 PoCsCross-site scripting (XSS) vulnerability in the file_download function in GNUBoard before 4.34.21 allows remote attackers to inject…
- CVE-2012-48764 PoCsStack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote…
- CVE-2012-48771 PoCCross-site request forgery (CSRF) vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 and earlier allows remote attackers to…
- CVE-2012-48782 PoCsAbsolute path traversal vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 allows remote administrators to read arbitrary…
- CVE-2012-48862 PoCsStack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code…
- CVE-2012-48896 PoCsMultiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web…
- CVE-2012-48913 PoCsCross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary…
- CVE-2012-49011 PoCCross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML…
- CVE-2012-49021 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in Template CMS 2.1.1 and earlier allow remote attackers to hijack the…
- CVE-2012-49051 PoCCross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web…
- CVE-2012-49061 PoCGoogle Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain…
- CVE-2012-49081 PoCGoogle Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local files via…
- CVE-2012-49091 PoCGoogle Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application.
- CVE-2012-49143 PoCsStack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a PDF document with a…
- CVE-2012-49152 PoCsDirectory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary…
- CVE-2012-49233 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2012-49243 PoCsBuffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote…
- CVE-2012-49252 PoCsMultiple SQL injection vulnerabilities in approve.php in Img Pals Photo Host 1.0 allow remote attackers to execute arbitrary SQL commands…
- CVE-2012-49262 PoCsapprove.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of…
- CVE-2012-49272 PoCsSQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute…
- CVE-2012-49281 PoCCross-site scripting (XSS) vulnerability in ow_updates/index.php in Oxwall 1.1.1 allows remote attackers to inject arbitrary web script or…
- CVE-2012-49293 PoCsThe TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without…
- CVE-2012-49321 PoCMultiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attackers to inject…
- CVE-2012-49331 PoCThe rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a…
- CVE-2012-49391 PoCCross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network…
- CVE-2012-49403 PoCsMultiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or…
- CVE-2012-49491 PoCSQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where…
- CVE-2012-49511 PoCMultiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote…
- CVE-2012-49571 PoCAbsolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a…
- CVE-2012-49581 PoCDirectory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a 126…
- CVE-2012-49593 PoCsDirectory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a…
- CVE-2012-49602 PoCsThe Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700,…
- CVE-2012-49692 PoCsKEVUse-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote…
- CVE-2012-49822 PoCsOpen redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to…
- CVE-2012-49881 PoCHeap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote…
- CVE-2012-49891 PoCCross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject…
- CVE-2012-49912 PoCsMultiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read,…
- CVE-2012-49922 PoCsMultiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode…
- CVE-2012-49932 PoCstorrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers to have an…
- CVE-2012-49962 PoCsMultiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the…
- CVE-2012-49972 PoCsDirectory traversal vulnerability in acp/index.php in AneCMS allows remote attackers to include and execute arbitrary local files via a ..…
- CVE-2012-49981 PoCCross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script or HTML via the q…
- CVE-2012-49991 PoCMercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted…