4.3
    Medium

    CVE-2012-6510

    Last Modified: 30 Apr 2012

    Multiple cross-site scripting (XSS) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PWRS or (2) Description field when posting a new vehicle; (3) news title when creating news; (4) Name when creating a sub user; (5) group name when creating a group; or (6) dealer name, (7) first name, or (8) last name when changing a profile.

    Source:Vulnerability-Lab
    Published:24 Jan 2013
    7.5
    High

    CVE-2012-6509

    Last Modified: 30 Apr 2012

    Unrestricted file upload vulnerability in NetArt Media Car Portal 3.0 allows remote attackers to execute arbitrary PHP code by uploading a file a double extension, as demonstrated by .php%00.jpg.

    Source:Vulnerability-Lab
    Published:24 Jan 2013
    6.8
    Medium

    CVE-2012-6508

    Last Modified: 30 Apr 2012

    Multiple cross-site request forgery (CSRF) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change arbitrary user passwords via a nouveau action in the security module to cars/ADMIN/index.php; (2) create a user or (3) create a sub user via a sub_accounts action in the home module to USERS/index.php; or (4) change profile information via an edit action in the profile module to USERS/index.php.

    Source:Vulnerability-Lab
    Published:24 Jan 2013
    4.3
    Medium

    CVE-2012-6506

    Last Modified: 13 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in zing.inc.php or (2) notes parameter in fws/pages-front/onecheckout.php.

    Source:Mehmet Ince
    Published:24 Jan 2013
    4.3
    Medium

    CVE-2012-6505

    Last Modified: 27 Apr 2012

    Cross-site scripting (XSS) vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:G13
    Published:24 Jan 2013
    7.5
    High

    CVE-2012-6504

    Last Modified: 27 Apr 2012

    SQL injection vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:G13
    Published:24 Jan 2013
    5
    Medium

    CVE-2012-6500

    Last Modified: 10 Jan 2012

    Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the fileget parameter in a profile action to index.php.

    Source:Or4nG.M4N
    Published:12 Jan 2013
    5.8
    Medium

    CVE-2012-6499

    Last Modified: 29 Mar 2015

    Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_to parameter.

    Source:Gianluca Brindisi
    Published:12 Jan 2013
    6
    Medium

    CVE-2012-6495

    Last Modified: 24 Jun 2013

    Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to overwrite arbitrary files via unspecified vectors. NOTE: this can be leveraged with CVE-2012-6081 to execute arbitrary code.

    Source:Metasploit
    Published:3 Jan 2013
    6.8
    Medium

    CVE-2012-6493

    Last Modified: 6 Jan 2013

    Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers to hijack the authentication of unspecified victims for requests that delete scan data and sites via a request to data/site/delete.

    Source:Robert Gilbert
    Published:4 Feb 2014
    9.3
    Critical

    CVE-2012-6470

    Last Modified: 14 Jul 2017

    Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a malformed image.

    Source:coolkaveh
    Published:2 Jan 2013
    6.1
    Medium

    CVE-2012-6448

    Last Modified: 12 Sept 2015

    Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:Christy Philip Mathew
    Published:27 Jan 2020
    6.8
    Medium

    CVE-2012-6434

    Last Modified: 3 Jan 2013

    Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) download_url, (2) download_url_extended, (3) download_author_email, (4) download_author_website, (5) download_image, (6) download_thumb, (7) download_visible, or (8) download_class parameter.

    Source:Joshua Reynolds
    Published:3 Jan 2013
    6.8
    Medium

    CVE-2012-6433

    Last Modified: 21 Feb 2013

    Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of administrators for requests that conduct XSS attacks via the news_title parameter in a create action.

    Source:Joshua Reynolds
    Published:3 Jan 2013
    4.3
    Medium

    CVE-2012-6430

    Last Modified: 15 Sept 2015

    Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded before December 19, 2012, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin.php. NOTE: this might be a duplicate of CVE-2008-4140.

    Source:High-Tech Bridge
    Published:24 Mar 2014
    10
    Critical

    CVE-2012-6429

    Last Modified: 15 Sept 2015

    Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to execute arbitrary code via a long string to the password argument.

    Source:High-Tech Bridge
    Published:4 Apr 2014
    9.3
    Critical

    CVE-2012-6422

    Last Modified: 11 Apr 2025

    The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which allows attackers to read or write arbitrary physical memory and gain privileges via a crafted application, as demonstrated by ExynosAbuse.

    Published:18 Dec 2012
    5
    Medium

    CVE-2012-6330

    Last Modified: 23 Dec 2012

    The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consumption) via a large integer in a %MAKETEXT% macro.

    Source:Metasploit
    Published:4 Jan 2013
    7.5
    High

    CVE-2012-6329

    Last Modified: 23 Dec 2012

    The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qualified method names during compilation of bracket notation, which allows context-dependent attackers to execute arbitrary commands via crafted input to an application that accepts translation strings from users, as demonstrated by the TWiki application before 5.1.3, and the Foswiki application 1.0.x through 1.0.10 and 1.1.x through 1.1.6.

    Source:Metasploit
    Published:4 Dec 2012
    Low

    CVE-2012-6315

    Last Modified: 24 Jan 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-0209. Reason: This candidate is a reservation duplicate of CVE-2013-0209. Notes: All CVE users should reference CVE-2013-0209 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Metasploit
    Published:23 Jan 2013
    5
    Medium

    CVE-2012-6313

    Last Modified: 9 Sept 2015

    simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a request that lacks a timezone, leading to disclosure of the installation path in a stack trace.

    Source:Aditya Balapure
    Published:11 Dec 2012
    4.3
    Medium

    CVE-2012-6312

    Last Modified: 2 Sept 2015

    Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter in a video-lead-form action to wp-admin/admin.php.

    Source:Aditya Balapure
    Published:11 Dec 2012
    8.8
    High

    CVE-2012-6307

    Last Modified: 10 Oct 2012

    A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious user execute arbitrary code

    Source:Jean Pascal Pereira
    Published:6 Feb 2020
    6.8
    Medium

    CVE-2012-6303

    Last Modified: 10 Oct 2016

    Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file.

    Source:Jean Pascal Pereira
    Published:28 Oct 2013
    6.5
    Medium

    CVE-2012-6290

    Last Modified: 25 Jan 2013

    SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to admin/admin_search/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

    Source:High-Tech Bridge SA
    Published:11 Mar 2014
    4.3
    Medium

    CVE-2012-6276

    Last Modified: 15 Feb 2013

    Directory traversal vulnerability in the web-based management interface on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via the URL parameter.

    Source:m-1-k-3
    Published:26 Jan 2013
    10
    Critical

    CVE-2012-6275

    Last Modified: 20 Feb 2013

    Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in a DUPF request.

    Source:Metasploit
    Published:24 Feb 2013
    5
    Medium

    CVE-2012-6274

    Last Modified: 20 Feb 2013

    BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors.

    Source:Metasploit
    Published:24 Feb 2013
    4.3
    Medium

    CVE-2012-6272

    Last Modified: 14 Sept 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.1 allow remote attackers to inject arbitrary web script or HTML via the topic parameter to html/index_main.htm in (1) help/sm/en/Output/wwhelp/wwhimpl/js/, (2) help/sm/es/Output/wwhelp/wwhimpl/js/, (3) help/sm/ja/Output/wwhelp/wwhimpl/js/, (4) help/sm/de/Output/wwhelp/wwhimpl/js/, (5) help/sm/fr/Output/wwhelp/wwhimpl/js/, (6) help/sm/zh/Output/wwhelp/wwhimpl/js/, (7) help/hip/en/msgguide/wwhelp/wwhimpl/js/, or (8) help/hip/en/msgguide/wwhelp/wwhimpl/common/.

    Source:Tenable NS
    Published:25 Jan 2013
    4.3
    Medium

    CVE-2012-6151

    Last Modified: 3 Dec 2015

    Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote attackers to cause a denial of service (crash or infinite loop, CPU consumption, and hang) by causing the AgentX subagent to timeout.

    Source:Ken Farnen
    Published:5 Sept 2012
    7.5
    High

    CVE-2012-6096

    Last Modified: 16 Jan 2013

    Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute arbitrary code via a long (1) host_name variable (host parameter) or (2) svc_description variable.

    Source:Metasploit
    Published:22 Jan 2013
    7.5
    High

    CVE-2012-6083

    Last Modified: 3 Aug 2014

    Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet.

    Source:Luigi Auriemma
    Published:23 Jan 2020
    6
    Medium

    CVE-2012-6081

    Last Modified: 24 Jun 2013

    Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as exploited in the wild in July 2012.

    Source:Metasploit
    Published:3 Jan 2013
    9.3
    Critical

    CVE-2012-6066

    Last Modified: 21 Dec 2016

    freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.

    Source:kingcope
    Published:4 Dec 2012
    6.4
    Medium

    CVE-2012-6050

    Last Modified: 1 May 2012

    The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other impacts via a request to download the router's DLLs or plugins, as demonstrated by roteros.dll.

    Source:PoURaN
    Published:27 Nov 2012
    5
    Medium

    CVE-2012-6048

    Last Modified: 9 May 2012

    Guitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file.

    Source:condis
    Published:27 Nov 2012
    6.8
    Medium

    CVE-2012-6047

    Last Modified: 9 May 2012

    Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that add a user to an arbitrary group via the users page in an adminpanel action to index.php.

    Source:DennSpec
    Published:27 Nov 2012
    10
    Critical

    CVE-2012-6046

    Last Modified: 29 May 2015

    Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php via the code parameter.

    Source:L3b-r1'z
    Published:27 Nov 2012
    4.3
    Medium

    CVE-2012-6045

    Last Modified: 29 May 2015

    Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Source:3spi0n
    Published:27 Nov 2012
    4.3
    Medium

    CVE-2012-6044

    Last Modified: 10 Oct 2016

    M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file.

    Source:JaMbA
    Published:26 Nov 2012
    4.3
    Medium

    CVE-2012-6043

    Last Modified: 29 Mar 2015

    Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.

    Source:Am!r
    Published:26 Nov 2012
    4.3
    Medium

    CVE-2012-6042

    Last Modified: 16 Mar 2012

    GPSMapEdit 1.1.73.2 allows user-assisted remote attackers to cause a denial of service (crash) via a long string in a lst file.

    Source:Julien Ahrens
    Published:26 Nov 2012
    6.8
    Medium

    CVE-2012-6041

    Last Modified: 30 Mar 2015

    Double free vulnerability in GreenBrowser before 6.0.1002, when the keyword search bar (F6) is activated, allows remote attackers to execute arbitrary code via a crafted iframe.

    Source:NCNIPC
    Published:26 Nov 2012
    4.3
    Medium

    CVE-2012-6040

    Last Modified: 29 Mar 2015

    Cross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Am!r
    Published:26 Nov 2012
    7.5
    High

    CVE-2012-6039

    Last Modified: 29 Nov 2016

    SQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows remote attackers to execute arbitrary SQL commands via the gal parameter.

    Source:Robert Cooper
    Published:26 Nov 2012
    6.5
    Medium

    CVE-2012-6038

    Last Modified: 10 Jan 2012

    admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remote authenticated users to read, edit, rename, move, copy and delete files via the (1) dir parameter in a fileman or (2) filemanview action. NOTE: this issue has been referred to as a "path traversal."

    Source:chap0
    Published:26 Nov 2012
    4.3
    Medium

    CVE-2012-6007

    Last Modified: 13 Dec 2012

    Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992.

    Source:Jacob Holcomb
    Published:19 Dec 2012
    6.8
    Medium

    CVE-2012-5992

    Last Modified: 13 Dec 2012

    Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via screens/aaa/mgmtuser_create.html or (2) insert XSS sequences via the headline parameter to screens/base/web_auth_custom.html, aka Bug ID CSCud50283.

    Source:Jacob Holcomb
    Published:19 Dec 2012
    6.3
    Medium

    CVE-2012-5991

    Last Modified: 13 Dec 2012

    screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to cause a denial of service (device reload) via a certain buttonClicked value in an internal webauth_type request, aka Bug ID CSCud50209.

    Source:Jacob Holcomb
    Published:19 Dec 2012
    9.3
    Critical

    CVE-2012-5975

    Last Modified: 5 Dec 2012

    The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 through 6.3.2 on UNIX and Linux, when old-style password authentication is enabled, allows remote attackers to bypass authentication via a crafted session involving entry of blank passwords, as demonstrated by a root login session from a modified OpenSSH client with an added input_userauth_passwd_changereq call in sshconnect2.c.

    Source:kingcope
    Published:4 Dec 2012