Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 396 541

Количество 396 541

nvd логотип

CVE-2012-5916

почти 14 лет назад

Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2) docs/upgrade/sedito_convert_to_utf8.optional.sql, or (3) system/install/install.parser.sql.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-5915

почти 14 лет назад

Neocrome Seditio build 161 and earlier allows remote attackers to obtain sensitive information via direct request to (1) view.php, (2) plugins/contact/lang/contact.en.lang.php, (3) system/lang/en/main.lang.php, (4) system/lang/en/message.lang.php, or (5) system/core/view/view.inc.php, which reveals the installation path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-5914

почти 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the sed_import function in system/functions.php in Neocrome Seditio build 160 and 161 allow remote attackers to inject arbitrary web script or HTML via the (1) newmsg or (2) rtext parameter. NOTE: some of these details are obtained from third party information.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2012-5913

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-5912

почти 14 лет назад

Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) page.php or (2) single.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-5911

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows remote attackers to inject arbitrary web script or HTML via the message body.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-5910

почти 14 лет назад

SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2012-5909

почти 14 лет назад

SQL injection vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to execute arbitrary SQL commands via the conditions[usergroup][] parameter in a search action to admin/index.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-5908

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to inject arbitrary web script or HTML via the conditions[usergroup][] parameter in a search action to admin/index.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-5907

почти 14 лет назад

Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter in a "3" action.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-5906

почти 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in GreenBrowser 6.1.0117 and 6.1.0216 allow remote attackers to inject arbitrary web script or HTML via (1) the URI in an about: page or (2) the last visited URL in the LastVisitWriteEn function in function.js.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-5905

почти 14 лет назад

Buffer overflow in KnFTPd 1.0.0 allows remote authenticated users to cause a denial of service (crash) via a long string in a FEAT command.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-5904

почти 14 лет назад

Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-5903

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the scheduled parameter to index.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-5902

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in ptk/lib/modal_bookmark.php in DFLabs PTK 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the arg4 parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-5901

почти 14 лет назад

DFLabs PTK 1.0.5 stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read logs, images, or reports via a direct request to the file in the (1) log, (2) images, or (3) report directory.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-5900

почти 14 лет назад

Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) OB_ID parameter in a single action to admin/action/objects.php, (2) AREA_ID parameter in a single action to admin/action/areas.php, or (3) start parameter in a show action to admin/action/pdf.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-5899

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the OTR_HEADS[] parameter in an edit action. NOTE: some of these details are obtained from third party information.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-5898

почти 14 лет назад

Cross-site request forgery (CSRF) vulnerability in SAMEDIA LandShop 0.9.2 allows remote attackers to hijack the authentication of administrators for requests that change account settings.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-5897

почти 14 лет назад

The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument.

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2012-5916

Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2) docs/upgrade/sedito_convert_to_utf8.optional.sql, or (3) system/install/install.parser.sql.

CVSS2: 5
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5915

Neocrome Seditio build 161 and earlier allows remote attackers to obtain sensitive information via direct request to (1) view.php, (2) plugins/contact/lang/contact.en.lang.php, (3) system/lang/en/main.lang.php, (4) system/lang/en/message.lang.php, or (5) system/core/view/view.inc.php, which reveals the installation path in an error message.

CVSS2: 5
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5914

Multiple cross-site scripting (XSS) vulnerabilities in the sed_import function in system/functions.php in Neocrome Seditio build 160 and 161 allow remote attackers to inject arbitrary web script or HTML via the (1) newmsg or (2) rtext parameter. NOTE: some of these details are obtained from third party information.

CVSS2: 2.6
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5913

Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.

CVSS2: 4.3
9%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5912

Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) page.php or (2) single.php.

CVSS2: 7.5
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5911

Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows remote attackers to inject arbitrary web script or HTML via the message body.

CVSS2: 4.3
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5910

SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter.

CVSS2: 6.5
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5909

SQL injection vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to execute arbitrary SQL commands via the conditions[usergroup][] parameter in a search action to admin/index.php.

CVSS2: 7.5
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5908

Cross-site scripting (XSS) vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to inject arbitrary web script or HTML via the conditions[usergroup][] parameter in a search action to admin/index.php.

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5907

Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter in a "3" action.

CVSS2: 5
8%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5906

Multiple cross-site scripting (XSS) vulnerabilities in GreenBrowser 6.1.0117 and 6.1.0216 allow remote attackers to inject arbitrary web script or HTML via (1) the URI in an about: page or (2) the last visited URL in the LastVisitWriteEn function in function.js.

CVSS2: 4.3
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5905

Buffer overflow in KnFTPd 1.0.0 allows remote authenticated users to cause a denial of service (crash) via a long string in a FEAT command.

CVSS2: 4
3%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5904

Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.

CVSS2: 6.8
6%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5903

Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the scheduled parameter to index.php.

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5902

Cross-site scripting (XSS) vulnerability in ptk/lib/modal_bookmark.php in DFLabs PTK 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the arg4 parameter.

CVSS2: 4.3
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5901

DFLabs PTK 1.0.5 stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read logs, images, or reports via a direct request to the file in the (1) log, (2) images, or (3) report directory.

CVSS2: 5
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5900

Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) OB_ID parameter in a single action to admin/action/objects.php, (2) AREA_ID parameter in a single action to admin/action/areas.php, or (3) start parameter in a show action to admin/action/pdf.php.

CVSS2: 7.5
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5899

Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the OTR_HEADS[] parameter in an edit action. NOTE: some of these details are obtained from third party information.

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5898

Cross-site request forgery (CSRF) vulnerability in SAMEDIA LandShop 0.9.2 allows remote attackers to hijack the authentication of administrators for requests that change account settings.

CVSS2: 6.8
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5897

The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument.

CVSS2: 9.3
4%
Низкий
почти 14 лет назад

Уязвимостей на страницу