CVE-2012-6000 to CVE-2012-6999
114 CVEs with public proof-of-concept exploits.
- CVE-2012-60071 PoCCross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software…
- CVE-2012-60382 PoCsadmin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which…
- CVE-2012-60392 PoCsSQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows remote attackers to…
- CVE-2012-60401 PoCCross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers to inject…
- CVE-2012-60411 PoCDouble free vulnerability in GreenBrowser before 6.0.1002, when the keyword search bar (F6) is activated, allows remote attackers to…
- CVE-2012-60422 PoCsGPSMapEdit 1.1.73.2 allows user-assisted remote attackers to cause a denial of service (crash) via a long string in a lst file.
- CVE-2012-60431 PoCCross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or…
- CVE-2012-60442 PoCsM-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file.
- CVE-2012-60451 PoCCross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers to inject…
- CVE-2012-60461 PoCStatic code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php…
- CVE-2012-60472 PoCsCross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the authentication of…
- CVE-2012-60482 PoCsGuitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file.
- CVE-2012-60502 PoCsThe winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the…
- CVE-2012-60666 PoCsfreeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an…
- CVE-2012-60671 PoCfreeFTPd.exe in freeFTPd through 1.0.11 allows remote attackers to bypass authentication via a crafted SFTP session, as demonstrated by an…
- CVE-2012-60815 PoCsMultiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py)…
- CVE-2012-60831 PoCFreeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet.
- CVE-2012-60965 PoCsMultiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before…
- CVE-2012-61511 PoCNet-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote attackers to cause a…
- CVE-2012-62721 PoCMultiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.1 allow remote…
- CVE-2012-62742 PoCsBigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary…
- CVE-2012-62752 PoCsMultiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified…
- CVE-2012-62761 PoCDirectory traversal vulnerability in the web-based management interface on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201…
- CVE-2012-62901 PoCSQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q…
- CVE-2012-63011 PoCThe Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted market:…
- CVE-2012-63032 PoCsHeap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer…
- CVE-2012-63071 PoCA vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious user execute…
- CVE-2012-63121 PoCCross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject arbitrary web…
- CVE-2012-63131 PoCsimple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information…
- CVE-2012-63293 PoCsThe _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and…
- CVE-2012-63302 PoCsThe localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to…
- CVE-2012-63421 PoCCross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the…
- CVE-2012-63471 PoCMultiple cross-site scripting (XSS) vulnerabilities in Java number format exception handling in FortiGate FortiDB before 4.4.2 allow…
- CVE-2012-63481 PoCCentrify Deployment Manager 2.1.0.283, as distributed in Centrify Suite before 2012.5, allows local users to (1) overwrite arbitrary files…
- CVE-2012-64221 PoCThe kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412…
- CVE-2012-64291 PoCBuffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote…
- CVE-2012-64301 PoCCross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded before December 19,…
- CVE-2012-64333 PoCsCross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the…
- CVE-2012-64342 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attackers to hijack the…
- CVE-2012-64481 PoCCross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2012-64491 PoCThe clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
- CVE-2012-64701 PoCOpera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a…
- CVE-2012-64932 PoCsCross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers to hijack the…
- CVE-2012-64952 PoCsMultiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py)…
- CVE-2012-64994 PoCsOpen redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers…
- CVE-2012-65002 PoCsDirectory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a…
- CVE-2012-65042 PoCsSQL injection vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to execute…
- CVE-2012-65052 PoCsCross-site scripting (XSS) vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to…
- CVE-2012-65062 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote attackers to inject…
- CVE-2012-65081 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to hijack the…
- CVE-2012-65091 PoCUnrestricted file upload vulnerability in NetArt Media Car Portal 3.0 allows remote attackers to execute arbitrary PHP code by uploading a…
- CVE-2012-65101 PoCMultiple cross-site scripting (XSS) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to inject arbitrary web script…
- CVE-2012-65111 PoCMultiple cross-site scripting (XSS) vulnerabilities in organizer/page/users.php in the Organizer plugin 1.2.1 for WordPress allow remote…
- CVE-2012-65121 PoCThe Organizer plugin 1.2.1 for WordPress allows remote attackers to obtain the installation path via unspecified vectors to (1)…
- CVE-2012-65131 PoCCross-site scripting (XSS) vulnerability in index.php/Admin_Preferences in gpEasy CMS 2.3.3 allows remote attackers to inject arbitrary…
- CVE-2012-65162 PoCsSQL injection vulnerability in PHP Ticket System Beta 1 allows remote attackers to execute arbitrary SQL commands via the q parameter to…
- CVE-2012-65172 PoCsMultiple cross-site scripting (XSS) vulnerabilities in DiY-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2012-65182 PoCsCross-site request forgery (CSRF) vulnerability in mod.php in DiY-CMS 1.0 allows remote attackers to hijack the authentication of…
- CVE-2012-65192 PoCsSQL injection vulnerability in modules/poll/index.php in DIY-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2012-65201 PoCMultiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbitrary SQL commands…
- CVE-2012-65224 PoCsDirectory traversal vulnerability in the getContent function in codes/wcms.php in w-CMS 2.01 allows remote attackers to read arbitrary…
- CVE-2012-65232 PoCsMultiple cross-site scripting (XSS) vulnerabilities in w-CMS 2.01 allow remote attackers to inject arbitrary web script or HTML via (1)…
- CVE-2012-65242 PoCsSQL injection vulnerability in kommentar.php in pGB 2.12 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2012-65252 PoCsSQL injection vulnerability in members.php in PHPBridges allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2012-65261 PoCSQL injection vulnerability in show_code.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via…
- CVE-2012-65281 PoCMultiple cross-site scripting (XSS) vulnerabilities in ATutor before 2.1 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2012-65293 PoCsMultiple SQL injection vulnerabilities in Marinet CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1)…
- CVE-2012-65306 PoCsStack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the create…
- CVE-2012-65331 PoCBuffer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 on Windows XP and Server 2003 allows…
- CVE-2012-65341 PoCNovell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request…
- CVE-2012-65501 PoCCross-site scripting (XSS) vulnerability in ZeroClipboard before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2012-65543 PoCsfunctions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP…
- CVE-2012-65552 PoCsCross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary…
- CVE-2012-65562 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote attackers to inject…
- CVE-2012-65572 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to inject…
- CVE-2012-65592 PoCsMultiple cross-site scripting (XSS) vulnerabilities in FreeNAC 3.02 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2012-65602 PoCsSQL injection vulnerability in deviceadd.php in FreeNAC 3.02 allows remote attackers to execute arbitrary SQL commands via the status…
- CVE-2012-65681 PoCBuffer overflow in the back-end component in Huawei UTPS 1.0 allows local users to gain privileges via a long IDS_PLUGIN_NAME string in a…
- CVE-2012-65842 PoCsMultiple SQL injection vulnerabilities in MYRE Realty Manager allow remote attackers to execute arbitrary SQL commands via the bathrooms1…
- CVE-2012-65852 PoCsCross-site scripting (XSS) vulnerability in search.php in MYRE Realty Manager allows remote attackers to inject arbitrary web script or…
- CVE-2012-65862 PoCsMultiple SQL injection vulnerabilities in MYRE Vacation Rental Software allow remote attackers to execute arbitrary SQL commands via the…
- CVE-2012-65872 PoCsCross-site scripting (XSS) vulnerability in vacation/1_mobile/alert_members.php in MYRE Vacation Rental Software allows remote attackers…
- CVE-2012-65882 PoCsSQL injection vulnerability in links.php in MYRE Business Directory allows remote attackers to execute arbitrary SQL commands via the cat…
- CVE-2012-65892 PoCsCross-site scripting (XSS) vulnerability in search.php in MYRE Business Directory allows remote attackers to inject arbitrary web script…
- CVE-2012-66081 PoCCross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject arbitrary web script…
- CVE-2012-66101 PoCPolycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as…
- CVE-2012-66112 PoCsAn issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux…
- CVE-2012-66131 PoCD-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.
- CVE-2012-66142 PoCsD-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as…
- CVE-2012-66221 PoCMultiple cross-site scripting (XSS) vulnerabilities in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for…
- CVE-2012-66241 PoCCross-site scripting (XSS) vulnerability in the SoundCloud Is Gold plugin 2.1 for WordPress allows remote attackers to inject arbitrary…
- CVE-2012-66251 PoCSQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote…
- CVE-2012-66262 PoCsSQL injection vulnerability in verify-user.php in b2ePMS 1.0 allows remote attackers to execute arbitrary SQL commands via the username…
- CVE-2012-66331 PoCCross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject…
- CVE-2012-66341 PoCwp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended…
- CVE-2012-66351 PoCwp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows…
- CVE-2012-66362 PoCsThe Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute…
- CVE-2012-66432 PoCsMultiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow remote attackers…
- CVE-2012-66449 PoCsMultiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2012-66491 PoCWordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.
- CVE-2012-66531 PoCUnspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack…
- CVE-2012-66582 PoCsMultiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2012-66631 PoCGeneral Electric D20ME devices are not properly configured and reveal plaintext passwords.
- CVE-2012-66642 PoCsMultiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to…
- CVE-2012-66651 PoCDirectory traversal vulnerability in index.php in phpMoneyBooks 1.0.4 allows remote attackers to read arbitrary files via a .. (dot dot)…
- CVE-2012-66661 PoCvBSeo before 3.6.0PL2 allows XSS via the member.php u parameter.
- CVE-2012-66672 PoCsCross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to…
- CVE-2012-66841 PoCCross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary…
- CVE-2012-66851 PoCNokogiri before 1.5.4 is vulnerable to XXE attacks
- CVE-2012-67051 PoCCross Site Scripting (XSS) exists in Jamroom before 4.2.7 via the Status Update field.
- CVE-2012-67071 PoCWordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext…
- CVE-2012-67081 PoCjQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors…
- CVE-2012-67102 PoCsext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an…
- CVE-2012-67201 PoCMultiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or…