261641
|
- |
|
welcart
|
welcart_plugin
|
Cross-site request forgery (CSRF) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that complete a p…
|
CWE-352
Origin Validation Error
|
CVE-2012-5178
|
2013-01-29 14:00 |
2012-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261642
|
- |
|
olivetoast
|
documents_pro_file_viewer
|
Directory traversal vulnerability in the Olive Toast Documents Pro File Viewer (formerly Files HD) app before 1.11.1 for iOS allows remote attackers to read or delete files by leveraging guest access.
|
CWE-22
Path Traversal
|
CVE-2012-5185
|
2013-01-29 14:00 |
2013-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261643
|
- |
|
cisco
|
telepresence_video_communication_servers_software
|
Cisco TelePresence Video Communication Server (VCS) X7.0.3 does not properly process certain search rules, which allows remote attackers to create conferences via an unspecified Conductor request, ak…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5444
|
2013-01-29 14:00 |
2013-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261644
|
- |
|
huawei
|
e585 e585u-82
|
The Huawei E585 device does not validate the status of admin sessions, which allows remote attackers to obtain sensitive user information and the session ID, and modify data, by leveraging access to …
|
CWE-20
Improper Input Validation
|
CVE-2012-5968
|
2013-01-29 14:00 |
2012-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261645
|
- |
|
huawei
|
e585 e585u-82
|
The Huawei E585 device allows remote attackers to cause a denial of service (NULL pointer dereference and device outage) via crafted HTTP requests, as demonstrated by unspecified vulnerability-scanni…
|
NVD-CWE-Other
|
CVE-2012-5970
|
2013-01-29 14:00 |
2012-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261646
|
- |
|
huawei
|
e585 e585u-82
|
Per: http://cwe.mitre.org/data/definitions/476.html
'CWE-476: NULL Pointer Dereference'
|
NVD-CWE-Other
|
CVE-2012-5970
|
2013-01-29 14:00 |
2012-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261647
|
- |
|
cisco
|
prime_lan_management_solution
|
Cisco Prime LAN Management Solution (LMS) 4.1 through 4.2.2 on Linux does not properly validate authentication and authorization requests in TCP sessions, which allows remote attackers to execute arb…
|
CWE-20
Improper Input Validation
|
CVE-2012-6392
|
2013-01-29 14:00 |
2013-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261648
|
- |
|
cisco
|
quad webex_social
|
Cross-site scripting (XSS) vulnerability in Cisco WebEx Social (formerly Cisco Quad) allows remote attackers to inject arbitrary web script or HTML via a crafted RSS service link, aka Bug ID CSCub619…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6397
|
2013-01-29 14:00 |
2013-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261649
|
- |
|
shawn_bradley
|
php_volunteer_management
|
SQL injection vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2012-6504
|
2013-01-29 14:00 |
2013-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261650
|
- |
|
shawn_bradley
|
php_volunteer_management
|
Cross-site scripting (XSS) vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6505
|
2013-01-29 14:00 |
2013-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|