4
    Medium

    CVE-2012-5335

    Last Modified: 10 Oct 2016

    Directory traversal vulnerability in Tiny Server 1.1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the URI of an HTTP request.

    Source:KaHPeSeSe
    Published:8 Oct 2012
    7.5
    High

    CVE-2012-5334

    Last Modified: 13 Aug 2012

    SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Source:Easy Laster
    Published:8 Oct 2012
    7.5
    High

    CVE-2012-5333

    Last Modified: 13 Aug 2012

    SQL injection vulnerability in page.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:r45c4l
    Published:8 Oct 2012
    6.8
    Medium

    CVE-2012-5331

    Last Modified: 14 Mar 2012

    Directory traversal vulnerability in asaanCart 0.9 allows remote attackers to include arbitrary local files via a .. (dot dot) in the page parameter to index.php.

    Source:Number 7
    Published:8 Oct 2012
    4.3
    Medium

    CVE-2012-5330

    Last Modified: 14 Mar 2012

    Multiple cross-site scripting (XSS) vulnerabilities in asaanCart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to calc.php, (2) chat.php, (3) register.php, or (4) index.php in libs/smarty_ajax/; or the (5) page parameter to libs/smarty_ajax/index.php.

    Source:Number 7
    Published:8 Oct 2012
    4
    Medium

    CVE-2012-5329

    Last Modified: 11 May 2015

    Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application crash) via a long string in an APPE command.

    Source:brock haun
    Published:8 Oct 2012
    6.8
    Medium

    CVE-2012-5326

    Last Modified: 21 Jan 2012

    Cross-site request forgery (CSRF) vulnerability in admin/function.php in IDevSpot iSupport 1.x allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via an administrators action.

    Source:Or4nG.M4N
    Published:8 Oct 2012
    9.3
    Critical

    CVE-2012-5324

    Last Modified: 29 Jan 2012

    Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry function or (2) sub_key parameter to the InitFromRegistry function.

    Source:LiquidWorm
    Published:8 Oct 2012
    6.8
    Medium

    CVE-2012-5323

    Last Modified: 30 Apr 2015

    Cross-site request forgery (CSRF) vulnerability in webconfig/admin_passwd/passwd.html/admin_passwd in Xavi X7968 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysUserName, sysPassword, and sysCfmPwd parameters.

    Source:Busindre
    Published:8 Oct 2012
    4.3
    Medium

    CVE-2012-5322

    Last Modified: 30 Apr 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Xavi X7968 allow remote attackers to inject arbitrary web script or HTML via the (1) pvcName parameter to webconfig/wan/confirm.html/confirm or (2) host_name_txtbox parameter to webconfig/lan/lan_config.html/local_lan_config.

    Source:Busindre
    Published:8 Oct 2012
    5.8
    Medium

    CVE-2012-5321

    Last Modified: 29 Apr 2015

    tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection."

    Source:sonyy
    Published:8 Oct 2012
    6.8
    Medium

    CVE-2012-5320

    Last Modified: 22 Feb 2012

    Cross-site request forgery (CSRF) vulnerability in password.cgi in Sagem F@ST 2604 253180972B allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.

    Source:KinG Of PiraTeS
    Published:8 Oct 2012
    6.8
    Medium

    CVE-2012-5319

    Last Modified: 1 May 2015

    Cross-site request forgery (CSRF) vulnerability in setup/security.cgi in D-Link DCS-900, DCS-2000, and DCS-5300 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the rootpass parameter.

    Source:Rigan Iimrigan
    Published:8 Oct 2012
    6.8
    Medium

    CVE-2012-5318

    Last Modified: 23 Jan 2012

    Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin 1.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with a double extension, then accessing it via a direct request to the file in the directory specified by the folder parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1125.

    Source:EgiX
    Published:8 Oct 2012
    4.3
    Medium

    CVE-2012-5315

    Last Modified: 16 Mar 2012

    Multiple cross-site scripting (XSS) vulnerabilities in php ireport 1.0 allow remote attackers to inject arbitrary web script or HTML via the message parameter to (1) messages_viewer.php, (2) home.php, or (3) history.php.

    Source:Or4nG.M4N
    Published:8 Oct 2012
    7.5
    High

    CVE-2012-5313

    Last Modified: 1 Apr 2015

    SQL injection vulnerability in forum.asp in Snitz Forums 2000 allows remote attackers to execute arbitrary SQL commands via the TOPIC_ID parameter.

    Source:snup
    Published:8 Oct 2012
    7.5
    High

    CVE-2012-5312

    Last Modified: 1 Apr 2015

    SQL injection vulnerability in Tribiq CMS allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:Skote Vahshat
    Published:8 Oct 2012
    9.3
    Critical

    CVE-2012-5306

    Last Modified: 28 Mar 2012

    Stack-based buffer overflow in the SelectDirectory method in DcsCliCtrl.dll in Camera Stream Client ActiveX Control, as used in D-Link DCS-5605 PTZ IP Network Camera, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string argument.

    Source:rgod
    Published:6 Oct 2012
    4.3
    Medium

    CVE-2012-5295

    Last Modified: 25 Mar 2015

    Cross-site scripting (XSS) vulnerability in login.cfm in FuseTalk Forums 3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the windowed parameter.

    Source:sonyy
    Published:4 Oct 2012
    7.5
    High

    CVE-2012-5294

    Last Modified: 25 Mar 2015

    SQL injection vulnerability in art_detalle.php in MyStore Xpress Tienda Virtual allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Arturo Zamora
    Published:4 Oct 2012
    7.5
    High

    CVE-2012-5293

    Last Modified: 16 Mar 2012

    Multiple PHP remote file inclusion vulnerabilities in SAPID CMS 1.2.3 Stable allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[root_path] parameter to usr/extensions/get_tree.inc.php or (2) root_path parameter to usr/extensions/get_infochannel.inc.php.

    Source:Opa Yong
    Published:4 Oct 2012
    7.5
    High

    CVE-2012-5292

    Last Modified: 27 Mar 2015

    Multiple SQL injection vulnerabilities in Atar2b CMS 4.0.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) gallery_e.php, (2) pageE.php, or (3) pageH.php.

    Source:BHG Security Center
    Published:4 Oct 2012
    7.5
    High

    CVE-2012-5291

    Last Modified: 4 Jan 2012

    SQL injection vulnerability in team.php in Posse Softball Director CMS allows remote attackers to execute arbitrary SQL commands via the idteam parameter.

    Source:Easy Laster
    Published:4 Oct 2012
    7.5
    High

    CVE-2012-5288

    Last Modified: 8 Jan 2012

    SQL injection vulnerability in page.php in phpMyDirectory 1.3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Serseri
    Published:4 Oct 2012
    7.5
    High

    CVE-2012-5244

    Last Modified: 16 Jan 2013

    Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) return, (2) display, (3) table, or (4) search parameter to functions/suggest.php; (5) the id parameter to functions/widgets.php, (6) the category parameter to functions/print.php; or (7) the name parameter to functions/ajax.php.

    Source:High-Tech Bridge SA
    Published:20 Oct 2014
    5
    Medium

    CVE-2012-5243

    Last Modified: 16 Jan 2013

    functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.

    Source:High-Tech Bridge SA
    Published:21 Oct 2014
    6.8
    Medium

    CVE-2012-5242

    Last Modified: 16 Jan 2013

    Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.

    Source:High-Tech Bridge SA
    Published:21 Oct 2014
    7.5
    High

    CVE-2012-5231

    Last Modified: 22 Jan 2012

    miniCMS 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code via a crafted (1) pagename or (2) area variable containing an executable extension, which is not properly handled by (a) update.php when writing files to content/, or (b) updatenews.php when writing files to content/news/.

    Source:Or4nG.M4N
    Published:1 Oct 2012
    4.3
    Medium

    CVE-2012-5229

    Last Modified: 3 Apr 2015

    Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the Slideshow Gallery2 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the border parameter.

    Source:Bret Hawk
    Published:1 Oct 2012
    4.3
    Medium

    CVE-2012-5228

    Last Modified: 16 Mar 2012

    Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the testtarget parameter. NOTE: some of these details are obtained from third party information.

    Source:Cyber-Crystal
    Published:1 Oct 2012
    7.5
    High

    CVE-2012-5227

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in administrer/tva.php in Peel SHOPPING 2.8 and 2.9 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Cyber-Crystal
    Published:1 Oct 2012
    4.3
    Medium

    CVE-2012-5226

    Last Modified: 4 Jan 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Peel SHOPPING 2.8 and 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) motclef parameter to achat/recherche.php or (2) PATH_INFO to index.php.

    Source:Cyber-Crystal
    Published:1 Oct 2012
    4.3
    Medium

    CVE-2012-5225

    Last Modified: 3 Apr 2015

    Cross-site scripting (XSS) vulnerability in webscr.php in xClick Cart 1.0.1 and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the shopping_url parameter.

    Source:sonyy
    Published:1 Oct 2012
    7.5
    High

    CVE-2012-5224

    Last Modified: 3 Apr 2015

    PHP remote file inclusion vulnerability in vb/includes/vba_cmps_include_bottom.php in vBadvanced CMPS 3.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pages[template] parameter.

    Source:PacketiK
    Published:1 Oct 2012
    7.5
    High

    CVE-2012-5223

    Last Modified: 31 Jan 2012

    The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted into a regular expression that is processed by the preg_replace function with the eval switch.

    Source:EgiX
    Published:1 Oct 2012
    10
    Critical

    CVE-2012-5201

    Last Modified: 26 Mar 2013

    Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1611.

    Source:Metasploit
    Published:9 Mar 2013
    6.1
    Medium

    CVE-2012-5193

    Last Modified: 24 Oct 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsletters/edition.php or the (3) username parameter to users/remind_password.php, (4) days parameter to stats/index.php, (5) login parameter to users/register.php, or (6) highlight parameter.

    Source:Trustwave's SpiderLabs
    Published:13 Nov 2019
    5
    Medium

    CVE-2012-5192

    Last Modified: 24 Oct 2012

    Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files via "''%2F" (dot dot encoded slash) sequences in the overlay_type parameter.

    Source:Trustwave's SpiderLabs
    Published:28 Jan 2014
    9.8
    Critical

    CVE-2012-5190

    Last Modified: 15 Sept 2015

    Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability

    Source:Include Security Research
    Published:21 Jan 2020
    7.5
    High

    CVE-2012-5167

    Last Modified: 22 Oct 2012

    Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field parameter to course_category/index_inline_editor_submit.php or (2) user/index_inline_editor_submit.php; or (3) id parameter to user/user_password.php.

    Source:High-Tech Bridge SA
    Published:22 Oct 2012
    7.5
    High

    CVE-2012-5159

    Last Modified: 10 Oct 2012

    phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.

    Source:Metasploit
    Published:25 Sept 2012
    10
    Critical

    CVE-2012-5106

    Last Modified: 1 Nov 2016

    Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via a long string in a PUT command.

    Source:Jacob Holcomb
    Published:20 Jun 2014
    4.3
    Medium

    CVE-2012-5105

    Last Modified: 27 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.4 allow remote attackers to inject arbitrary web script or HTML via the dbsel parameter to (1) main.php or (2) index.php; or (3) nsextt parameter to index.php.

    Source:Stefan Schurtz
    Published:23 Sept 2012
    4.3
    Medium

    CVE-2012-5104

    Last Modified: 26 Mar 2015

    Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the Loginname parameter.

    Source:sonyy
    Published:23 Sept 2012
    4.3
    Medium

    CVE-2012-5102

    Last Modified: 27 Mar 2015

    Cross-site scripting (XSS) vulnerability in inc/extensions.php in VertrigoServ 2.25 allows remote attackers to inject arbitrary web script or HTML via the ext parameter.

    Source:Stefan Schurtz
    Published:23 Sept 2012
    5
    Medium

    CVE-2012-5100

    Last Modified: 26 Mar 2015

    Directory traversal vulnerability in HServer 0.1.1 allows remote attackers to read arbitrary files via a (1) ..%5c (dot dot encoded backslash) or (2) %2e%2e%5c (encoded dot dot backslash) in the PATH_INFO.

    Source:demonalex
    Published:23 Sept 2012
    4.3
    Medium

    CVE-2012-5099

    Last Modified: 25 Mar 2015

    Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.

    Source:H4ckCity Security Team
    Published:23 Sept 2012
    7.5
    High

    CVE-2012-5098

    Last Modified: 2 Jan 2012

    Multiple SQL injection vulnerabilities in Php-X-Links, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to rate.php, (2) cid parameter to view.php, or (3) t parameter to pop.php.

    Source:H4ckCity Security Team
    Published:23 Sept 2012
    10
    Critical

    CVE-2012-5088

    Last Modified: 24 Jan 2013

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

    Source:Metasploit
    Published:16 Oct 2012
    9.8
    Critical

    CVE-2012-5076

    Last Modified: 24 Jan 2013

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.

    Source:Metasploit
    Published:16 Oct 2012