CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2012-4937

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack web sessions via a jsession_id cookie.

    Published: 18 Nov 2012
    3.5
    Low

    CVE-2012-4938

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web interface in Pattern Insight 2.3 allows remote authenticated administrators to inject arbitrary web script or HTML via the banner message.

    Published: 18 Nov 2012
    4.3
    Medium

    CVE-2012-4942

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to inject arbitrary web script or HTML via an arbitrary text field.

    Published: 18 Nov 2012
    6.8
    Medium

    CVE-2012-4943

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to hijack the authentication of arbitrary users for requests that modify (1) passwords, (2) accounts, or (3) permissions.

    Published: 18 Nov 2012
    10
    Critical

    CVE-2012-4944

    Last Modified: 11 Apr 2025

    Multiple unrestricted file upload vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary code by uploading a file via an unspecified page.

    Published: 18 Nov 2012
    7.5
    High

    CVE-2012-4945

    Last Modified: 11 Apr 2025

    Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection" issue.

    Published: 18 Nov 2012
    5
    Medium

    CVE-2012-4946

    Last Modified: 11 Apr 2025

    Agile FleetCommander and FleetCommander Kiosk before 4.08 use an XOR format for password encryption, which makes it easier for context-dependent attackers to obtain sensitive information by reading a key file and the encrypted strings.

    Published: 18 Nov 2012
    5
    Medium

    CVE-2012-4947

    Last Modified: 11 Apr 2025

    Agile FleetCommander and FleetCommander Kiosk before 4.08 store database credentials in cleartext, which allows remote attackers to obtain sensitive information via requests to unspecified pages.

    Published: 18 Nov 2012
    4.3
    Medium

    CVE-2012-4950

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via crafted characters that are not properly handled during construction of error messages.

    Published: 18 Nov 2012
    7.5
    High

    CVE-2012-4941

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 18 Nov 2012
    5
    Medium

    CVE-2012-4575

    Last Modified: 11 Apr 2025

    The add_database function in objects.c in the pgbouncer pooler 1.5.2 for PostgreSQL allows remote attackers to cause a denial of service (daemon outage) via a long database name in a request.

    Published: 18 Nov 2012
    7.8
    High

    CVE-2012-4957

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a /FSF/CMD request with a full pathname in a PATH element of an SRS record.

    Published: 18 Nov 2012
    7.8
    High

    CVE-2012-4958

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a 126 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.

    Published: 18 Nov 2012
    10
    Critical

    CVE-2012-4959

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.

    Published: 18 Nov 2012
    10
    Critical

    CVE-2012-4956

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements in an SRS record.

    Published: 18 Nov 2012
    2.1
    Low

    CVE-2012-5530

    Last Modified: 11 Apr 2025

    The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.

    Published: 18 Nov 2012
    4.3
    Medium

    CVE-2012-5888

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Basic SEO Features (seo_basics) extension before 0.8.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Nov 2012
    4.3
    Medium

    CVE-2012-5889

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the powermail extension before 1.6.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Nov 2012
    5
    Medium

    CVE-2012-5890

    Last Modified: 11 Apr 2025

    The Front End User Registration (sr_feuser_register) extension before 2.6.2 for TYPO3 allows remote attackers to obtain user names and passwords via the (1) edit perspective or (2) autologin feature.

    Published: 17 Nov 2012
    6.8
    Medium

    CVE-2012-5891

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in photo/pass.php in DAlbum 1.44 build 174 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an add action, (2) change user passwords via a change action, or (3) delete a user via a delete action.

    Published: 17 Nov 2012
    5
    Medium

    CVE-2012-5892

    Last Modified: 11 Apr 2025

    Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the configuration database via a direct request for data/havalite.db3.

    Published: 17 Nov 2012
    10
    Critical

    CVE-2012-5895

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in iRODS before 3.1 have unknown impact and attack vectors.

    Published: 17 Nov 2012
    9.3
    Critical

    CVE-2012-5897

    Last Modified: 11 Apr 2025

    The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument.

    Published: 17 Nov 2012
    6.8
    Medium

    CVE-2012-5898

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in SAMEDIA LandShop 0.9.2 allows remote attackers to hijack the authentication of administrators for requests that change account settings.

    Published: 17 Nov 2012
    4.3
    Medium

    CVE-2012-5899

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the OTR_HEADS[] parameter in an edit action. NOTE: some of these details are obtained from third party information.

    Published: 17 Nov 2012
    4.3
    Medium

    CVE-2012-5903

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the scheduled parameter to index.php.

    Published: 17 Nov 2012
    6.8
    Medium

    CVE-2012-5904

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.

    Published: 17 Nov 2012
    4
    Medium

    CVE-2012-5905

    Last Modified: 11 Apr 2025

    Buffer overflow in KnFTPd 1.0.0 allows remote authenticated users to cause a denial of service (crash) via a long string in a FEAT command.

    Published: 17 Nov 2012
    4.3
    Medium

    CVE-2012-5906

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in GreenBrowser 6.1.0117 and 6.1.0216 allow remote attackers to inject arbitrary web script or HTML via (1) the URI in an about: page or (2) the last visited URL in the LastVisitWriteEn function in function.js.

    Published: 17 Nov 2012
    7.5
    High

    CVE-2012-5909

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to execute arbitrary SQL commands via the conditions[usergroup][] parameter in a search action to admin/index.php.

    Published: 17 Nov 2012
    6.5
    Medium

    CVE-2012-5910

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter.

    Published: 17 Nov 2012
    4.3
    Medium

    CVE-2012-5911

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows remote attackers to inject arbitrary web script or HTML via the message body.

    Published: 17 Nov 2012
    7.5
    High

    CVE-2012-5912

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) page.php or (2) single.php.

    Published: 17 Nov 2012
    2.6
    Low

    CVE-2012-5914

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the sed_import function in system/functions.php in Neocrome Seditio build 160 and 161 allow remote attackers to inject arbitrary web script or HTML via the (1) newmsg or (2) rtext parameter. NOTE: some of these details are obtained from third party information.

    Published: 17 Nov 2012
    4.3
    Medium

    CVE-2012-5917

    Last Modified: 11 Apr 2025

    SnackAmp 3.1.3 allows remote attackers to cause a denial of service (application crash) via a long string in an aiff file.

    Published: 17 Nov 2012
    7.5
    High

    CVE-2012-5894

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in hava_post.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the postId parameter.

    Published: 17 Nov 2012
    7.5
    High

    CVE-2012-5900

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) OB_ID parameter in a single action to admin/action/objects.php, (2) AREA_ID parameter in a single action to admin/action/areas.php, or (3) start parameter in a show action to admin/action/pdf.php.

    Published: 17 Nov 2012
    4.3
    Medium

    CVE-2012-5902

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ptk/lib/modal_bookmark.php in DFLabs PTK 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the arg4 parameter.

    Published: 17 Nov 2012
    4.3
    Medium

    CVE-2012-5908

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to inject arbitrary web script or HTML via the conditions[usergroup][] parameter in a search action to admin/index.php.

    Published: 17 Nov 2012
    4.3
    Medium

    CVE-2012-5913

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.

    Published: 17 Nov 2012
    5
    Medium

    CVE-2012-5916

    Last Modified: 11 Apr 2025

    Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2) docs/upgrade/sedito_convert_to_utf8.optional.sql, or (3) system/install/install.parser.sql.

    Published: 17 Nov 2012
    5
    Medium

    CVE-2012-5901

    Last Modified: 11 Apr 2025

    DFLabs PTK 1.0.5 stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read logs, images, or reports via a direct request to the file in the (1) log, (2) images, or (3) report directory.

    Published: 17 Nov 2012
    5
    Medium

    CVE-2012-5907

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter in a "3" action.

    Published: 17 Nov 2012
    6.8
    Medium

    CVE-2012-5893

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in hava_upload.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading a file with a .php;.gif extension, then accessing it via a direct request to the file in tmp/files/.

    Published: 17 Nov 2012
    10
    Critical

    CVE-2012-5896

    Last Modified: 11 Apr 2025

    The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not properly implement the Add method, which allows remote attackers to execute arbitrary code via a memory address in the first argument, related to an "uninitialized pointer."

    Published: 17 Nov 2012
    5
    Medium

    CVE-2012-5915

    Last Modified: 11 Apr 2025

    Neocrome Seditio build 161 and earlier allows remote attackers to obtain sensitive information via direct request to (1) view.php, (2) plugins/contact/lang/contact.en.lang.php, (3) system/lang/en/main.lang.php, (4) system/lang/en/message.lang.php, or (5) system/core/view/view.inc.php, which reveals the installation path in an error message.

    Published: 17 Nov 2012
    4.3
    Medium

    CVE-2012-5856

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Uk Cookie (aka uk-cookie) plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Nov 2012
    5
    Medium

    CVE-2012-5172

    Last Modified: 11 Apr 2025

    The Asial Monaca Debugger application before 1.4.2 for Android allows remote attackers to obtain sensitive (1) account or (2) session ID information in a system log file via a crafted application.

    Published: 16 Nov 2012
    4.3
    Medium

    CVE-2012-4189

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled during construction of a tabular report, as demonstrated by the Version field.

    Published: 16 Nov 2012
    5
    Medium

    CVE-2012-4197

    Last Modified: 11 Apr 2025

    Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 allows remote attackers to read attachment descriptions from private bugs via an obsolete=1 insert action.

    Published: 16 Nov 2012