9.3
    Critical

    CVE-2013-0025

    Last Modified: 23 Feb 2013

    Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability."

    Source:Scott Bell
    Published:13 Feb 2013
    9.3
    Critical

    CVE-2013-0019

    Last Modified: 6 Dec 2016

    Use-after-free vulnerability in Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer COmWindowProxy Use After Free Vulnerability."

    Source:Skylined
    Published:13 Feb 2013
    7.2
    High

    CVE-2013-0008

    Last Modified: 11 Feb 2013

    win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."

    Source:0vercl0k
    Published:9 Jan 2013
    9.3
    Critical

    CVE-2013-0007

    Last Modified: 11 Apr 2025

    Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability."

    Published:9 Jan 2013
    6.1
    Medium

    CVE-2012-6708

    Last Modified: 25 Mar 2021

    jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the '<' character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the '<' character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common.

    Source:MiningOmerta
    Published:21 Mar 2017
    Unknown

    CVE-2012-6679

    https://www.exploit-db.com/exploits/18668

    6.1
    Medium

    CVE-2012-6667

    Last Modified: 22 Mar 2012

    Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action.

    Source:ToiL
    Published:11 Jan 2018
    4.3
    Medium

    CVE-2012-6665

    Last Modified: 22 Mar 2012

    Directory traversal vulnerability in index.php in phpMoneyBooks 1.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a different vulnerability than CVE-2012-1669. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue might have been fixed in 1.0.3.

    Source:Mark Stanislav
    Published:17 Nov 2014
    9.1
    Critical

    CVE-2012-6664

    Last Modified: 23 Mar 2017

    Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a .. (dot dot) in the (1) get or (2) put commands.

    Source:Metasploit
    Published:21 Jun 2024
    4.3
    Medium

    CVE-2012-6658

    Last Modified: 23 Jul 2012

    Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName configuration in snmpd.conf. NOTE: this entry was SPLIT from CVE-2012-2956 per ADT2 due to different vulnerability types.

    Source:dookie
    Published:17 Sept 2014
    7.5
    High

    CVE-2012-6653

    Last Modified: 5 Nov 2012

    Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack vectors.

    Source:Ashiyane Digital Security Team
    Published:6 Aug 2014
    9.8
    Critical

    CVE-2012-6649

    Last Modified: 11 Jun 2012

    WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.

    Source:Adrien Thierry
    Published:23 Jan 2020
    4.3
    Medium

    CVE-2012-6644

    Last Modified: 27 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4) videos.php; (5) query parameter to search_result.php; or (6) type parameter to view_collection.php or (7) view_item.php.

    Source:YaDoY666
    Published:8 Apr 2014
    7.5
    High

    CVE-2012-6643

    Last Modified: 27 Mar 2015

    Multiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow remote attackers to execute arbitrary SQL commands via the time parameter to (1) videos.php or (2) channels.php. NOTE: some of these details are obtained from third party information.

    Source:YaDoY666
    Published:8 Apr 2014
    6.8
    Medium

    CVE-2012-6636

    Last Modified: 23 Mar 2017

    The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection API within crafted JavaScript code that is loaded into the WebView component in an application targeted to API level 16 or earlier, a related issue to CVE-2013-4710.

    Source:Metasploit
    Published:3 Mar 2014
    7.5
    High

    CVE-2012-6626

    Last Modified: 15 May 2012

    SQL injection vulnerability in verify-user.php in b2ePMS 1.0 allows remote attackers to execute arbitrary SQL commands via the username field.

    Source:Jean Pascal Pereira
    Published:16 Jan 2014
    7.5
    High

    CVE-2012-6625

    Last Modified: 13 Sept 2011

    SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the groupid parameter in an editgroup action.

    Source:Miroslav Stampar
    Published:16 Jan 2014
    4.3
    Medium

    CVE-2012-6624

    Last Modified: 5 Jun 2015

    Cross-site scripting (XSS) vulnerability in the SoundCloud Is Gold plugin 2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the width parameter in a soundcloud_is_gold_player_preview action to wp-admin/admin-ajax.php.

    Source:Heine Pedersen
    Published:16 Jan 2014
    4.3
    Medium

    CVE-2012-6622

    Last Modified: 4 Jun 2015

    Multiple cross-site scripting (XSS) vulnerabilities in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) groupid parameter in an editgroup action or (2) usergroup_id parameter in an edit_usergroup action.

    Source:Heine Pedersen
    Published:16 Jan 2014
    4.3
    Medium

    CVE-2012-6608

    Last Modified: 3 Sept 2015

    Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the Page parameter.

    Source:cheki
    Published:25 Nov 2013
    4.3
    Medium

    CVE-2012-6589

    Last Modified: 14 Nov 2012

    Cross-site scripting (XSS) vulnerability in search.php in MYRE Business Directory allows remote attackers to inject arbitrary web script or HTML via the look parameter.

    Source:d3b4g
    Published:25 Aug 2013
    7.5
    High

    CVE-2012-6588

    Last Modified: 14 Nov 2012

    SQL injection vulnerability in links.php in MYRE Business Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:d3b4g
    Published:25 Aug 2013
    4.3
    Medium

    CVE-2012-6587

    Last Modified: 14 Nov 2012

    Cross-site scripting (XSS) vulnerability in vacation/1_mobile/alert_members.php in MYRE Vacation Rental Software allows remote attackers to inject arbitrary web script or HTML via the link_idd parameter in a login action.

    Source:d3b4g
    Published:25 Aug 2013
    7.5
    High

    CVE-2012-6586

    Last Modified: 14 Nov 2012

    Multiple SQL injection vulnerabilities in MYRE Vacation Rental Software allow remote attackers to execute arbitrary SQL commands via the (1) garage1 or (2) bathrooms1 parameter to vacation/1_mobile/search.php, or (3) unspecified input to vacation/widgate/request_more_information.php.

    Source:d3b4g
    Published:25 Aug 2013
    4.3
    Medium

    CVE-2012-6585

    Last Modified: 14 Nov 2012

    Cross-site scripting (XSS) vulnerability in search.php in MYRE Realty Manager allows remote attackers to inject arbitrary web script or HTML via the cat_id1 parameter.

    Source:d3b4g
    Published:25 Aug 2013
    7.5
    High

    CVE-2012-6584

    Last Modified: 14 Nov 2012

    Multiple SQL injection vulnerabilities in MYRE Realty Manager allow remote attackers to execute arbitrary SQL commands via the bathrooms1 parameter to (1) demo2/search.php or (2) search.php.

    Source:d3b4g
    Published:25 Aug 2013
    6.9
    Medium

    CVE-2012-6568

    Last Modified: 15 Oct 2012

    Buffer overflow in the back-end component in Huawei UTPS 1.0 allows local users to gain privileges via a long IDS_PLUGIN_NAME string in a plug-in configuration file.

    Source:Dark-Puzzle
    Published:20 Jun 2013
    7.5
    High

    CVE-2012-6560

    Last Modified: 19 May 2012

    SQL injection vulnerability in deviceadd.php in FreeNAC 3.02 allows remote attackers to execute arbitrary SQL commands via the status parameter.

    Source:blake
    Published:23 May 2013
    4.3
    Medium

    CVE-2012-6559

    Last Modified: 19 May 2012

    Multiple cross-site scripting (XSS) vulnerabilities in FreeNAC 3.02 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) mac, (3) graphtype, (4) name, or (5) type parameter to stats.php; or (6) comment parameter to deviceadd.php.

    Source:blake
    Published:23 May 2013
    4.3
    Medium

    CVE-2012-6557

    Last Modified: 21 May 2012

    Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web script or HTML via the (1) AboutMe/RealName, (2) AboutMe/Name, (3) AboutMe/Quote, (4) AboutMe/Loc, (5) AboutMe/Emp, (6) AboutMe/JobTit, (7) AboutMe/HS, (8) AboutMe/Col, (9) AboutMe/Bio, (10) AboutMe/Inter, (11) AboutMe/Mus, (12) AboutMe/Gam, (13) AboutMe/Mov, (14) AboutMe/FTV, or (15) AboutMe/Bks parameter to the Edit My Details page. NOTE: some of these details are obtained from third party information.

    Source:Henry Hoggard
    Published:23 May 2013
    4.3
    Medium

    CVE-2012-6556

    Last Modified: 21 May 2012

    Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web script or HTML via the (1) User/FirstName or (2) User/LastName parameter to the edit user page. NOTE: some of these details are obtained from third party information.

    Source:Henry Hoggard
    Published:23 May 2013
    4.3
    Medium

    CVE-2012-6555

    Last Modified: 21 May 2012

    Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web script or HTML via the discussion title.

    Source:Henry Hoggard
    Published:23 May 2013
    6.5
    Medium

    CVE-2012-6554

    Last Modified: 19 May 2012

    functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the message[message_text] parameter to chat/add_messag, which is not properly handled when executing the preg_replace function with the eval switch.

    Source:Metasploit
    Published:23 May 2013
    4.3
    Medium

    CVE-2012-6550

    Last Modified: 28 Sept 2015

    Cross-site scripting (XSS) vulnerability in ZeroClipboard before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via "the clipText returned from the flash object," a different vulnerability than CVE-2013-1808.

    Source:MustLive
    Published:28 Mar 2013
    4.3
    Medium

    CVE-2012-6534

    Last Modified: 4 Oct 2012

    Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data retention policies via a search-results "Save Query As" "Save As Retention Policy" action.

    Source:Piotr Chmylkowski
    Published:29 Mar 2013
    4.4
    Medium

    CVE-2012-6533

    Last Modified: 24 Nov 2017

    Buffer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 on Windows XP and Server 2003 allows local users to gain privileges via a crafted application.

    Source:Nikita Tarakanov
    Published:18 Feb 2013
    7.1
    High

    CVE-2012-6530

    Last Modified: 18 Jan 2012

    Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the create folder permission to execute arbitrary code via a crafted request.

    Source:Craig Freyman
    Published:31 Jan 2013
    7.5
    High

    CVE-2012-6529

    Last Modified: 29 Mar 2015

    Multiple SQL injection vulnerabilities in Marinet CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) galleryphoto.php or (2) gallery.php; or the roomid parameter to (3) room.php or (4) room2.php.

    Source:H4ckCity Security Team
    Published:31 Jan 2013
    4.3
    Medium

    CVE-2012-6528

    Last Modified: 31 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) themes/default/tile_search/index.tmpl.php, (2) login.php, (3) search.php, (4) password_reminder.php, (5) login.php/jscripts/infusion, (6) login.php/mods/_standard/flowplayer, (7) browse.php/jscripts/infusion/framework/fss, (8) registration.php/themes/default/ie_styles.css, (9) about.php, or (10) themes/default/social/basic_profile.tmpl.php.

    Source:Stefan Schurtz
    Published:31 Jan 2013
    7.5
    High

    CVE-2012-6526

    Last Modified: 31 Mar 2015

    SQL injection vulnerability in show_code.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the code_id parameter.

    Source:Lazmania61
    Published:31 Jan 2013
    7.5
    High

    CVE-2012-6525

    Last Modified: 18 Jan 2012

    SQL injection vulnerability in members.php in PHPBridges allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:3spi0n
    Published:31 Jan 2013
    7.5
    High

    CVE-2012-6524

    Last Modified: 18 Jan 2012

    SQL injection vulnerability in kommentar.php in pGB 2.12 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:3spi0n
    Published:31 Jan 2013
    4.3
    Medium

    CVE-2012-6523

    Last Modified: 10 Jan 2012

    Multiple cross-site scripting (XSS) vulnerabilities in w-CMS 2.01 allow remote attackers to inject arbitrary web script or HTML via (1) the p parameter in the getMenus function in codes/wcms.php; or the COMMENT parameter in (2) blog.php, (3) guestbook.php, or (4) forum.php in codes/. NOTE: some of these details are obtained from third party information.

    Source:th3.g4m3_0v3r
    Published:31 Jan 2013
    5
    Medium

    CVE-2012-6522

    Last Modified: 6 Apr 2012

    Directory traversal vulnerability in the getContent function in codes/wcms.php in w-CMS 2.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. NOTE: some of these details are obtained from third party information.

    Source:Black-ID
    Published:31 Jan 2013
    7.5
    High

    CVE-2012-6520

    Last Modified: 8 May 2015

    Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbitrary SQL commands via the (1) select_sort or (2) opt_search_select parameters. NOTE: this issue could not be reproduced by third parties.

    Source:Stefan Schurtz
    Published:24 Jan 2013
    7.5
    High

    CVE-2012-6519

    Last Modified: 2 May 2012

    SQL injection vulnerability in modules/poll/index.php in DIY-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the start parameter to mod.php.

    Source:Vulnerability-Lab
    Published:24 Jan 2013
    6.8
    Medium

    CVE-2012-6518

    Last Modified: 2 May 2012

    Cross-site request forgery (CSRF) vulnerability in mod.php in DiY-CMS 1.0 allows remote attackers to hijack the authentication of administrators for requests that create a poll via an add action to the poll module.

    Source:Vulnerability-Lab
    Published:24 Jan 2013
    4.3
    Medium

    CVE-2012-6517

    Last Modified: 2 May 2012

    Multiple cross-site scripting (XSS) vulnerabilities in DiY-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) question parameter to in /modules/poll/add.php or (2) question or (3) answer parameter to modules/poll/edit.php.

    Source:Vulnerability-Lab
    Published:24 Jan 2013
    7.5
    High

    CVE-2012-6516

    Last Modified: 13 Aug 2012

    SQL injection vulnerability in PHP Ticket System Beta 1 allows remote attackers to execute arbitrary SQL commands via the q parameter to index.php.

    Source:G13
    Published:24 Jan 2013
    4.3
    Medium

    CVE-2012-6513

    Last Modified: 25 May 2015

    Cross-site scripting (XSS) vulnerability in index.php/Admin_Preferences in gpEasy CMS 2.3.3 allows remote attackers to inject arbitrary web script or HTML via the jsoncallback parameter.

    Source:Jakub Galczyk
    Published:24 Jan 2013