CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2012-4262

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in myCare2x allow remote attackers to inject arbitrary web script or HTML via the (1) name_last, (2) name_first, (3) name_middle, or (4) name_maiden parameter to modules/patient/mycare_pid.php; (5) favorites or (6) lang parameter to modules/nursing/mycare_ward_print.php; (7) aktion or (8) callurl parameter to modules/patient/mycare2x_pat_info.php; or (9) ln parameter to modules/drg/mycare2x_proc_search.php.

    Published: 13 Aug 2012
    7.5
    High

    CVE-2012-2324

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.7 allow remote administrators to execute arbitrary SQL commands via unspecified vectors in the (1) user search or (2) Mail Log in the Admin Control Panel (ACP).

    Published: 13 Aug 2012
    5
    Medium

    CVE-2012-4257

    Last Modified: 11 Apr 2025

    Yaqas (Yet Another Question & Answer System) 1.0 Alpha 1 allows remote attackers to obtain sensitive information via an invalid character in the PHPSESSID, which reveals the installation path in an error message.

    Published: 13 Aug 2012
    5.1
    Medium

    CVE-2012-4252

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of administrators for requests that (1) remove file access restriction via a deletehtaccess action, (2) drop a database via a kill value in a db action, (3) uninstall the application via a 101 value in the phase parameter to learn/cubemail/install.php, (4) delete config.php via a 2 value in the phase parameter to learn/cubemail/install.php, (5) change a password via a schutz action, or (6) execute arbitrary SQL commands via the sql_statement parameter to learn/cubemail/sql.php.

    Published: 13 Aug 2012
    5
    Medium

    CVE-2012-4256

    Last Modified: 11 Apr 2025

    The jNews (com_jnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveals the installation path in an error message.

    Published: 13 Aug 2012
    4.3
    Medium

    CVE-2012-3458

    Last Modified: 11 Apr 2025

    Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.

    Published: 13 Aug 2012
    5.8
    Medium

    CVE-2012-3482

    Last Modified: 11 Apr 2025

    Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (crash and delayed delivery of inbound mail) via a crafted NTLM response that triggers an out-of-bounds read in the base64 decoder, or (2) obtain sensitive information from memory via an NTLM Type 2 message with a crafted Target Name structure, which triggers an out-of-bounds read.

    Published: 13 Aug 2012
    3.5
    Low

    CVE-2012-3476

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in (1) application/views/admin/layout.php and (2) themes/default/views/header.php in the Ushahidi Platform before 2.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to a site name.

    Published: 12 Aug 2012
    4.3
    Medium

    CVE-2012-2587

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in AfterLogic MailSuite Pro 6.3 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with a crafted SRC attribute of (1) an IFRAME element or (2) a SCRIPT element.

    Published: 12 Aug 2012
    7.5
    High

    CVE-2012-3470

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in application/libraries/api/MY_Countries_Api_Object.php in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary SQL commands via vectors related to _get_countries functions.

    Published: 12 Aug 2012
    7.5
    High

    CVE-2012-3471

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the edit functions in (1) application/controllers/admin/reports.php and (2) application/controllers/members/reports.php in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary SQL commands via an incident id.

    Published: 12 Aug 2012
    6.4
    Medium

    CVE-2012-3472

    Last Modified: 11 Apr 2025

    The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows remote attackers to list, delete, or organize messages via a GET request.

    Published: 12 Aug 2012
    6.4
    Medium

    CVE-2012-3473

    Last Modified: 11 Apr 2025

    The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.

    Published: 12 Aug 2012
    5
    Medium

    CVE-2012-3474

    Last Modified: 11 Apr 2025

    The comments API in application/libraries/api/MY_Comments_Api_Object.php in the Ushahidi Platform before 2.5 allows remote attackers to obtain sensitive information about the e-mail address, IP address, and other attributes of the author of a comment via an API function call.

    Published: 12 Aug 2012
    7.5
    High

    CVE-2012-3475

    Last Modified: 11 Apr 2025

    The installer in the Ushahidi Platform before 2.5 omits certain calls to the exit function, which allows remote attackers to obtain administrative privileges via unspecified vectors.

    Published: 12 Aug 2012
    4.3
    Medium

    CVE-2012-2573

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in T-dah WebMail 3.2.0-2.3 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression property, (3) a CSS expression property in the STYLE attribute of an arbitrary element, (4) an ONLOAD attribute of a BODY element, (5) a crafted SRC attribute of an IFRAME element, (6) a crafted CONTENT attribute of an HTTP-EQUIV="refresh" META element, or (7) a data: URL in the CONTENT attribute of an HTTP-EQUIV="refresh" META element.

    Published: 12 Aug 2012
    4.3
    Medium

    CVE-2012-2585

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression property, (3) a CSS expression property in the STYLE attribute of an arbitrary element, or (4) a crafted SRC attribute of an IFRAME element, or an e-mail message subject with (5) a SCRIPT element, (6) a CSS expression property in the STYLE attribute of an arbitrary element, (7) a crafted SRC attribute of an IFRAME element, (8) a crafted CONTENT attribute of an HTTP-EQUIV="refresh" META element, or (9) a data: URL in the CONTENT attribute of an HTTP-EQUIV="refresh" META element.

    Published: 12 Aug 2012
    7.5
    High

    CVE-2012-3469

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the messages admin functionality in application/controllers/admin/messages.php, (2) application/libraries/api/MY_Checkin_Api_Object.php, (3) application/controllers/admin/messages/reporters.php, or (4) the location API in application/libraries/api/MY_Locations_Api_Object.php and application/models/location.php.

    Published: 12 Aug 2012
    4.3
    Medium

    CVE-2012-2571

    Last Modified: 27 Jan 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WinWebMail Server 3.8.1.6 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression property, (3) a CSS expression property in the STYLE attribute of an arbitrary element, (4) a crafted SRC attribute of an IFRAME element, or (5) UTF-7 text in an HTTP-EQUIV="CONTENT-TYPE" META element.

    Published: 12 Aug 2012
    4.3
    Medium

    CVE-2012-2590

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ESCON SupportPortal Professional Edition 3.0 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted SRC attribute of an IFRAME element, (3) a crafted CONTENT attribute of an HTTP-EQUIV="Set-Cookie" META element, or (4) an innerHTML attribute within an XML document.

    Published: 12 Aug 2012
    7.5
    High

    CVE-2012-3468

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the verify function in application/controllers/alerts.php, (2) the save_all function in application/models/settings.php, or (3) the media type to the timeline function in application/controllers/json.php.

    Published: 12 Aug 2012
    5
    Medium

    CVE-2012-4069

    Last Modified: 11 Apr 2025

    Dir2web 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct request for system/db/website.db.

    Published: 12 Aug 2012
    7.5
    High

    CVE-2012-4070

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote attackers to execute arbitrary SQL commands via the oid parameter in a homepage action to index.php.

    Published: 12 Aug 2012
    9.3
    Critical

    CVE-2012-4248

    Last Modified: 11 Apr 2025

    The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow remote attackers to have an unspecified impact via vectors involving the (1) dev.log, (2) lipc.set, (3) lipc.get, or (4) todo.scheduleItems method, a different vulnerability than CVE-2012-4249.

    Published: 12 Aug 2012
    4.3
    Medium

    CVE-2012-2584

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) the Cascading Style Sheets (CSS) expression property in conjunction with a CSS comment within the STYLE attribute of an IMG element, (2) the CSS expression property in conjunction with multiple CSS comments within the STYLE attribute of an arbitrary element, or (3) an innerHTML attribute within an XML document.

    Published: 12 Aug 2012
    10
    Critical

    CVE-2012-4249

    Last Modified: 11 Apr 2025

    The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a string, as demonstrated by using lipc-set-prop to set an LIPC property, a different vulnerability than CVE-2012-4248.

    Published: 12 Aug 2012
    4.3
    Medium

    CVE-2012-2577

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf file.

    Published: 12 Aug 2012
    6.8
    Medium

    CVE-2012-2602

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to Admin/Accounts/Add/OrionAccount.aspx or (2) modify account privileges via a ynAdminRights action to Admin/Accounts/EditAccount.aspx.

    Published: 12 Aug 2012
    5
    Medium

    CVE-2012-2963

    Last Modified: 11 Apr 2025

    The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require authentication for the gwt/BugReport script, which allows remote attackers to obtain sensitive information by downloading a .tgz file.

    Published: 12 Aug 2012
    5
    Medium

    CVE-2012-2964

    Last Modified: 11 Apr 2025

    The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the network for XML documents.

    Published: 12 Aug 2012
    7.5
    High

    CVE-2012-2965

    Last Modified: 11 Apr 2025

    Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown impact and remote attack vectors, related to an "HTTP Parameter Contamination" issue.

    Published: 12 Aug 2012
    7.5
    High

    CVE-2012-2966

    Last Modified: 11 Apr 2025

    Caucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis of POST parameters, which has unspecified impact and remote attack vectors.

    Published: 12 Aug 2012
    6.4
    Medium

    CVE-2012-2969

    Last Modified: 11 Apr 2025

    Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created files via a %00 sequence in a pathname within an HTTP request.

    Published: 12 Aug 2012
    5
    Medium

    CVE-2012-2968

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to create files in arbitrary directories via a .. (dot dot) in a pathname within an HTTP request.

    Published: 12 Aug 2012
    7.5
    High

    CVE-2012-2967

    Last Modified: 11 Apr 2025

    Caucho Quercus, as distributed in Resin before 4.0.29, does not properly implement the == (equals sign equals sign) operator for comparisons, which has unspecified impact and context-dependent attack vectors.

    Published: 12 Aug 2012
    2.1
    Low

    CVE-2012-3457

    Last Modified: 11 Apr 2025

    PNP4Nagios 0.6 through 0.6.16 uses world-readable permissions for process_perfdata.cfg, which allows local users to obtain the Gearman shared secret by reading the file.

    Published: 12 Aug 2012
    2.6
    Low

    CVE-2012-3952

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/index.php in phpList before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the unconfirmed parameter to the user page.

    Published: 12 Aug 2012
    7.5
    High

    CVE-2012-3953

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via the delete parameter to the editattributes page.

    Published: 12 Aug 2012
    4.3
    Medium

    CVE-2012-4246

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter; or the (2) footer, (3) status, or (4) testtarget parameter in the send page.

    Published: 12 Aug 2012
    4.3
    Medium

    CVE-2012-4247

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) remote_user, (2) remote_database, (3) remote_userprefix, (4) remote_password, or (5) remote_prefix parameter to the import4 page; or the (6) id parameter to the bouncerule page.

    Published: 12 Aug 2012
    4.6
    Medium

    CVE-2012-3480

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.

    Published: 12 Aug 2012
    7.5
    High

    CVE-2012-4035

    Last Modified: 11 Apr 2025

    The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password parameters to index.php.

    Published: 12 Aug 2012
    7.5
    High

    CVE-2012-4034

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to the send page, (2) email parameter to the forget page, (3) password parameter to the forum_archive page, (4) section parameter to the management page, (5) section_id parameter to the managementreply page, (6) member_id parameter to the new_password page, or (7) subjectid parameter to the tags page to index.php.

    Published: 12 Aug 2012
    3.3
    Low

    CVE-2012-0786

    Last Modified: 11 Apr 2025

    The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augnew file.

    Published: 11 Aug 2012
    6.8
    Medium

    CVE-2012-4386

    Last Modified: 11 Apr 2025

    The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.

    Published: 11 Aug 2012
    5
    Medium

    CVE-2012-4387

    Last Modified: 11 Apr 2025

    Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.

    Published: 11 Aug 2012
    6.5
    Medium

    CVE-2012-3132

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to execute arbitrary SQL commands via vectors involving CREATE INDEX with a CTXSYS.CONTEXT INDEXTYPE and DBMS_STATS.GATHER_TABLE_STATS.

    Published: 10 Aug 2012
    7.5
    High

    CVE-2012-3554

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the RSGallery2 (com_rsgallery2) component before 2.3.0 for Joomla! 1.5.x, and before 3.2.0 for Joomla! 2.5.x, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 10 Aug 2012
    5
    Medium

    CVE-2012-4235

    Last Modified: 11 Apr 2025

    The RSGallery2 (com_rsgallery2) component before 3.2.0 for Joomla! 2.5.x does not place index.html files in image directories, which allows remote attackers to list image filenames via a request for a directory URI.

    Published: 10 Aug 2012
    4.3
    Medium

    CVE-2012-4071

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the comments module in the RSGallery2 (com_rsgallery2) component before 2.3.0 for Joomla! 1.5.x, and before 3.2.0 for Joomla! 2.5.x, allows remote attackers to inject arbitrary web script or HTML via crafted BBCode markup in a comment.

    Published: 10 Aug 2012