260851
|
- |
|
bestpractical
|
rt
|
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject multiple Content-Disposition HTTP headers and possibly conduct cross-site scripting (XSS) attacks vi…
|
CWE-79
Cross-site Scripting
|
CVE-2013-3372
|
2013-08-27 22:02 |
2013-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260852
|
- |
|
intel
|
wimax_network_service
|
The Trace_OpenLogFile function in InfraStack/OSDependent/Linux/InfraStackModules/TraceModule/TraceModule.c in the Trace module in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMA…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4216
|
2013-08-27 22:01 |
2013-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260853
|
- |
|
feedweb
|
feedweb
|
Cross-site scripting (XSS) vulnerability in widget_remove.php in the Feedweb plugin before 1.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the …
|
CWE-79
Cross-site Scripting
|
CVE-2013-3720
|
2013-08-27 21:58 |
2013-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260854
|
- |
|
apple
|
podcast_producer
|
Podcast Capture in Podcast Producer for Apple Mac OS X 10.5.2 invokes a subtask with passwords in command line arguments, which allows local users to read the passwords via process listings.
|
CWE-200
Information Exposure
|
CVE-2008-0993
|
2013-08-27 14:56 |
2008-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260855
|
- |
|
aiocp
|
aiocp
|
Cross-site scripting (XSS) vulnerability in shared/code/cp_authorization.php in All In One Control Panel (AIOCP) before 1.3.016 allows remote attackers to inject arbitrary web script or HTML via unsp…
|
NVD-CWE-Other
|
CVE-2007-2625
|
2013-08-27 14:41 |
2007-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260856
|
- |
|
ruby-lang
|
ruby
|
Ruby 1.9.3 before patchlevel 286 and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the (1) exc_to_s or (2) name_err_…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4464
|
2013-08-27 12:27 |
2013-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260857
|
- |
|
mantisbt
|
mantisbt
|
The access_has_bug_level function in core/access_api.php in MantisBT before 1.2.9 does not properly restrict access when the private_bug_view_threshold is set to an array, which allows remote attacke…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1118
|
2013-08-27 12:21 |
2012-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260858
|
- |
|
mantisbt
|
mantisbt
|
bug_actiongroup.php in MantisBT before 1.2.9 does not properly check the report_bug_threshold permission of the receiving project when moving a bug report, which allows remote authenticated users wit…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1122
|
2013-08-27 12:21 |
2012-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260859
|
- |
|
mantisbt
|
mantisbt
|
MantisBT 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by view_all_inc.ph…
|
CWE-200
Information Exposure
|
CVE-2011-3755
|
2013-08-27 12:17 |
2011-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260860
|
- |
|
mantisbt
|
mantisbt
|
Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php in MantisBT before 1.2.7 allow remote attackers to inject arbitrary web script or HTML via a parameter, as demonstrated by the pr…
|
CWE-79
Cross-site Scripting
|
CVE-2011-2938
|
2013-08-27 12:15 |
2011-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|