261581
|
- |
|
carlosgavazzi
|
eos-box_photovoltaic_monitoring_system_firmware eos-box_photovoltaic_monitoring_system
|
Multiple SQL injection vulnerabilities in Carlo Gavazzi EOS-Box with firmware before 1.0.0.1080_2.1.10 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, a similar issu…
|
CWE-89
SQL Injection
|
CVE-2012-6427
|
2012-12-24 14:00 |
2012-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261582
|
- |
|
vmware
|
hyperic_hq
|
The monitor perl script in the Sybase database plug-in in SpringSource Hyperic HQ before 4.3 allows local users to obtain the database password by listing the process and its arguments.
|
CWE-200
Information Exposure
|
CVE-2009-2899
|
2012-12-24 14:00 |
2012-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261583
|
- |
|
oracle
|
glassfish_web_space_server10.0
|
Directory traversal vulnerability in the Liferay component in Oracle Sun GlassFish Web Space Server before 10.0 Update 7 Patch 2 has unknown impact and attack vectors.
|
CWE-22
Path Traversal
|
CVE-2012-1712
|
2012-12-22 00:05 |
2012-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261584
|
- |
|
meizu samsung
|
mx galaxy_note_2 galaxy_s2
|
The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which al…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6422
|
2012-12-21 14:00 |
2012-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261585
|
- |
|
cat norman rising-global symantec
|
quick_heal norman_antivirus_\&_antispyware rising_antivirus endpoint_protection
|
The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attack…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1421
|
2012-12-20 14:00 |
2012-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261586
|
- |
|
alex_barth
|
data
|
Multiple cross-site scripting (XSS) vulnerabilities in the Data module 6.x-1.x before 6.x-1.0 and 7.x-1.x before 7.x-1.0-alpha3 for Drupal allow remote authenticated users with the administer data ta…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1654
|
2012-12-20 14:00 |
2012-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261587
|
- |
|
siemens
|
simatic_pcs7 wincc
|
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote at…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3030
|
2012-12-20 14:00 |
2012-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261588
|
- |
|
simplemachines
|
smf
|
Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote attackers to conduct SQL injection attacks, obtain sensitiv…
|
CWE-20
Improper Input Validation
|
CVE-2011-1130
|
2012-12-20 14:00 |
2011-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261589
|
- |
|
tedfelix
|
acpid2
|
samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DB…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-2777
|
2012-12-20 14:00 |
2012-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261590
|
- |
|
burnsy
|
jbshop_plugin
|
Cross-site scripting (XSS) vulnerability in jbshop.php in the jbShop plugin for e107 7 allows remote attackers to inject arbitrary web script or HTML via the item_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2011-5186
|
2012-12-20 14:00 |
2012-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|