260961
|
- |
|
centrify
|
centrify_deployment_manager centrify_suite
|
Centrify Deployment Manager 2.1.0.283, as distributed in Centrify Suite before 2012.5, allows local users to (1) overwrite arbitrary files via a symlink attack on the adcheckDMoutput temporary file, …
|
CWE-59
Link Following
|
CVE-2012-6348
|
2013-01-8 14:00 |
2013-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260962
|
- |
|
carlosgavazzi
|
eos-box_photovoltaic_monitoring_system_firmware eos-box_photovoltaic_monitoring_system
|
Carlo Gavazzi EOS-Box with firmware before 1.0.0.1080_2.1.10 establishes multiple hardcoded accounts, which makes it easier for remote attackers to obtain administrative access by reading a password …
|
CWE-255
Credentials Management
|
CVE-2012-6428
|
2013-01-8 14:00 |
2012-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260963
|
- |
|
redhat
|
certificate_system
|
The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 does not properly handle interruptions of token format operations, which allows remote attackers to cause a den…
|
NVD-CWE-Other
|
CVE-2012-4555
|
2013-01-8 00:41 |
2013-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260964
|
- |
|
redhat
|
enterprise_virtualization_manager
|
Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, in certain unspecified conditions, does not lock the desktop screen between SPICE sessions, which allows local users with access to a vi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4316
|
2013-01-7 23:54 |
2013-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260965
|
- |
|
steven_jones
|
context
|
The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access to block content, which allows remote attackers to obtain sensitive information…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5655
|
2013-01-7 14:00 |
2013-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260966
|
- |
|
moinmo
|
moinmoin
|
Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6082
|
2013-01-7 14:00 |
2013-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260967
|
- |
|
lemonldap-ng
|
lemonldap\
|
LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6426
|
2013-01-7 14:00 |
2013-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260968
|
- |
|
sensiolabs
|
symfony
|
Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly e…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6431
|
2013-01-7 14:00 |
2012-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260969
|
- |
|
e107
|
e107
|
Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of administrators for requests that conduct XSS attacks v…
|
CWE-352
Origin Validation Error
|
CVE-2012-6433
|
2013-01-7 14:00 |
2013-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260970
|
- |
|
e107
|
e107
|
Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL…
|
CWE-352
Origin Validation Error
|
CVE-2012-6434
|
2013-01-7 14:00 |
2013-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|