257041
|
- |
|
yaml-fuer-drupal
|
linkchecker
|
includes/linkchecker.pages.inc in the Link checker module 6.x-2.x before 6.x-2.5 for Drupal does not properly enforce access permissions on broken links, which allows remote attackers to obtain sensi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1642
|
2012-08-29 13:00 |
2012-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257042
|
- |
|
jason_savino
|
fp
|
The Faster Permissions module 7.x-2.x before 7.x-1.2 for Drupal does not check the "administer permissions" permission, which allows remote attackers to modify access permissions via unspecified vect…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1643
|
2012-08-29 13:00 |
2012-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257043
|
- |
|
wimleers
|
cdn
|
The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the "Far Future expiration" option enabled, allows remote attackers to read arbitrary PHP files via unspecified ve…
|
CWE-200
Information Exposure
|
CVE-2012-1645
|
2012-08-29 13:00 |
2012-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257044
|
- |
|
wellintech
|
kingview
|
WellinTech KingSCADA 3.0 uses a cleartext base64 format for storage of passwords in user.db, which allows context-dependent attackers to obtain sensitive information by reading this file.
|
CWE-255
Credentials Management
|
CVE-2012-1977
|
2012-08-29 13:00 |
2012-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257045
|
- |
|
mybb
|
mybb
|
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.7 allow remote administrators to execute arbitrary SQL commands via unspecified vectors in the (1) user search or (2) M…
|
CWE-89
SQL Injection
|
CVE-2012-2324
|
2012-08-29 13:00 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257046
|
- |
|
afterlogic
|
mailsuite_pro
|
Multiple cross-site scripting (XSS) vulnerabilities in AfterLogic MailSuite Pro 6.3 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with a crafted SRC attribu…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2587
|
2012-08-29 13:00 |
2012-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257047
|
- |
|
samsung
|
kies
|
The MASetupCaller ActiveX control before 1.4.2012.508 in MASetupCaller.dll in MarkAny ContentSAFER, as distributed in Samsung KIES before 2.3.2.12074_13_13, does not properly implement unspecified me…
|
CWE-94
Code Injection
|
CVE-2012-2990
|
2012-08-29 13:00 |
2012-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257048
|
- |
|
roundcube
|
webmail
|
Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube Webmail 0.8.0 allows remote attackers to inject arbitrary web script or HTML by using "javascript:" in an href attribu…
|
CWE-79
Cross-site Scripting
|
CVE-2012-3508
|
2012-08-29 13:00 |
2012-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257049
|
- |
|
atmail
|
atmail_open
|
@Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to execute arbitrary code via an e-mail attachment with an executable extension, leading to the creation of an executabl…
|
NVD-CWE-Other
|
CVE-2012-1916
|
2012-08-29 12:48 |
2012-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257050
|
- |
|
atmail
|
atmail_open
|
Per: http://www.kb.cert.org/vuls/id/743555 'CWE-434: Unrestricted Upload of File with Dangerous Type'
|
NVD-CWE-Other
|
CVE-2012-1916
|
2012-08-29 12:48 |
2012-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|