Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 395 605

Количество 395 605

nvd логотип

CVE-2012-2970

около 14 лет назад

The Synel SY-780/A Time & Attendance terminal allows remote attackers to cause a denial of service (device hang) via network traffic to port (1) 1641, (2) 3734, or (3) 3735.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2012-2969

около 14 лет назад

Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created files via a %00 sequence in a pathname within an HTTP request.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2012-2968

около 14 лет назад

Directory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to create files in arbitrary directories via a .. (dot dot) in a pathname within an HTTP request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-2967

около 14 лет назад

Caucho Quercus, as distributed in Resin before 4.0.29, does not properly implement the == (equals sign equals sign) operator for comparisons, which has unspecified impact and context-dependent attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-2966

около 14 лет назад

Caucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis of POST parameters, which has unspecified impact and remote attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-2965

около 14 лет назад

Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown impact and remote attack vectors, related to an "HTTP Parameter Contamination" issue.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-2964

около 14 лет назад

The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the network for XML documents.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-2963

около 14 лет назад

The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require authentication for the gwt/BugReport script, which allows remote attackers to obtain sensitive information by downloading a .tgz file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-2962

около 14 лет назад

SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated users to execute arbitrary SQL commands via the q parameter.

CVSS2: 6.5
EPSS: Средний
nvd логотип

CVE-2012-2961

около 14 лет назад

SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-2960

около 14 лет назад

Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-2959

больше 14 лет назад

Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote attackers to hijack the authentication of administrators for requests that change passwords.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2012-2957

около 14 лет назад

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue.

CVSS2: 7.2
EPSS: Средний
nvd логотип

CVE-2012-2956

около 12 лет назад

SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v2.json. NOTE: this entry was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6658 is for the XSS.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2012-2955

около 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allow remote attackers to inject arbitrary web script or HTML via the query string.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-2953

около 14 лет назад

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2012-2952

больше 14 лет назад

SQL injection vulnerability in add_ons.php in Jaow 2.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the add_ons parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-2951

больше 14 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6587. Reason: This candidate is a duplicate of CVE-2007-6587. Notes: All CVE users should reference CVE-2007-6587 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2012-2950

больше 6 лет назад

Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2012-2949

больше 14 лет назад

The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2012-2970

The Synel SY-780/A Time & Attendance terminal allows remote attackers to cause a denial of service (device hang) via network traffic to port (1) 1641, (2) 3734, or (3) 3735.

CVSS2: 7.8
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2969

Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created files via a %00 sequence in a pathname within an HTTP request.

CVSS2: 6.4
4%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2968

Directory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to create files in arbitrary directories via a .. (dot dot) in a pathname within an HTTP request.

CVSS2: 5
3%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2967

Caucho Quercus, as distributed in Resin before 4.0.29, does not properly implement the == (equals sign equals sign) operator for comparisons, which has unspecified impact and context-dependent attack vectors.

CVSS2: 7.5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2966

Caucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis of POST parameters, which has unspecified impact and remote attack vectors.

CVSS2: 7.5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2965

Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown impact and remote attack vectors, related to an "HTTP Parameter Contamination" issue.

CVSS2: 7.5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2964

The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the network for XML documents.

CVSS2: 5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2963

The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require authentication for the gwt/BugReport script, which allows remote attackers to obtain sensitive information by downloading a .tgz file.

CVSS2: 5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2962

SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated users to execute arbitrary SQL commands via the q parameter.

CVSS2: 6.5
67%
Средний
около 14 лет назад
nvd логотип
CVE-2012-2961

SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS2: 7.5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2960

Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file.

CVSS2: 4.3
3%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2959

Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote attackers to hijack the authentication of administrators for requests that change passwords.

CVSS2: 5.1
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-2957

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue.

CVSS2: 7.2
59%
Средний
около 14 лет назад
nvd логотип
CVE-2012-2956

SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v2.json. NOTE: this entry was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6658 is for the XSS.

CVSS2: 6.5
1%
Низкий
около 12 лет назад
nvd логотип
CVE-2012-2955

Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allow remote attackers to inject arbitrary web script or HTML via the query string.

CVSS2: 4.3
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2953

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.

CVSS2: 10
67%
Средний
около 14 лет назад
nvd логотип
CVE-2012-2952

SQL injection vulnerability in add_ons.php in Jaow 2.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the add_ons parameter.

CVSS2: 7.5
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-2951

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6587. Reason: This candidate is a duplicate of CVE-2007-6587. Notes: All CVE users should reference CVE-2007-6587 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

больше 14 лет назад
nvd логотип
CVE-2012-2950

Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information.

CVSS3: 8.1
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2012-2949

The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application.

CVSS2: 10
4%
Низкий
больше 14 лет назад

Уязвимостей на страницу