4.3
    Medium

    CVE-2012-4344

    Last Modified: 22 Jul 2012

    Cross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold 15.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the SNMP system name of the attacking host.

    Source:muts
    Published:15 Aug 2012
    4.3
    Medium

    CVE-2012-4336

    Last Modified: 16 Aug 2015

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) an arbitrary parameter.

    Source:High-Tech Bridge
    Published:15 Sept 2012
    7.8
    High

    CVE-2012-4335

    Last Modified: 27 Oct 2016

    Samsung NET-i viewer 1.37.120316 allows remote attackers to cause a denial of service (infinite loop) via a negative size value in a TCP request to (1) NiwMasterService or (2) NiwStorageService. NOTE: some of these details are obtained from third party information.

    Source:Luigi Auriemma
    Published:14 Aug 2012
    10
    Critical

    CVE-2012-4334

    Last Modified: 27 Oct 2016

    The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Source:Luigi Auriemma
    Published:14 Aug 2012
    10
    Critical

    CVE-2012-4333

    Last Modified: 27 Oct 2016

    Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i viewer 1.37.120316 allow remote attackers to execute arbitrary code via a long string in the fname parameter. NOTE: some of these details are obtained from third party information.

    Source:Luigi Auriemma
    Published:14 Aug 2012
    7.8
    High

    CVE-2012-4330

    Last Modified: 19 Apr 2012

    The Samsung D6000 TV and possibly other products allows remote attackers to cause a denial of service (crash) via a long string in certain fields, as demonstrated by the MAC address field, possibly a buffer overflow.

    Source:Luigi Auriemma
    Published:14 Aug 2012
    7.8
    High

    CVE-2012-4329

    Last Modified: 19 Apr 2012

    The Samsung D6000 TV and possibly other products allow remote attackers to cause a denial of service (continuous restart) via a crafted controller name.

    Source:Luigi Auriemma
    Published:14 Aug 2012
    6.8
    Medium

    CVE-2012-4325

    Last Modified: 8 Apr 2012

    Cross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts.

    Source:Dr.NaNo
    Published:14 Aug 2012
    9.8
    Critical

    CVE-2012-4284

    Last Modified: 27 Oct 2016

    A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code

    Source:zx2c4
    Published:10 Jan 2020
    7.5
    High

    CVE-2012-4282

    Last Modified: 29 May 2015

    SQL injection vulnerability in photo.php in Trombinoscope 3.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Ramdan Yantu
    Published:13 Aug 2012
    7.5
    High

    CVE-2012-4281

    Last Modified: 13 May 2012

    Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid parameter to (1) holiday.php or (2) holiday_book.php, (3) id parameter to pages.php, (4) fid parameter to admin/airline-edit.php, or (5) cid parameter to admin/customer-edit.php.

    Source:Vulnerability-Lab
    Published:13 Aug 2012
    6.8
    Medium

    CVE-2012-4280

    Last Modified: 13 May 2012

    Multiple cross-site request forgery (CSRF) vulnerabilities in admin/agenteditor.php in Free Realty 3.1-0.6 allow remote attackers to hijack the authentication of administrators for requests that (1) add an agent via an addagent action or (2) modify an agent.

    Source:Vulnerability-Lab
    Published:13 Aug 2012
    7.5
    High

    CVE-2012-4279

    Last Modified: 13 May 2012

    Multiple SQL injection vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to agentdisplay.php or (2) edit parameter to admin/admin.php.

    Source:Vulnerability-Lab
    Published:13 Aug 2012
    4.3
    Medium

    CVE-2012-4278

    Last Modified: 13 May 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) notes parameter to (a) admin/agenteditor.php; (2) title, (3) previewdesc, (4) fulldesc, or (5) notes parameter (b) to agentadmin.php or (c) in an addlisting action to agentadmin.php; or unspecified vectors to (d) admin/adminfeatures.php.

    Source:Vulnerability-Lab
    Published:13 Aug 2012
    4.3
    Medium

    CVE-2012-4267

    Last Modified: 13 May 2012

    Cross-site scripting (XSS) vulnerability in user/register in Sockso 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the name parameter.

    Source:Ciaran McNally
    Published:13 Aug 2012
    4.3
    Medium

    CVE-2012-4266

    Last Modified: 13 May 2012

    Cross-site scripting (XSS) vulnerability in client_details.php in Proman Xpress 5.0.1 allows remote attackers to inject arbitrary web script or HTML via the cl_comments parameter. NOTE: some of these details are obtained from third party information.

    Source:Vulnerability-Lab
    Published:13 Aug 2012
    7.5
    High

    CVE-2012-4265

    Last Modified: 13 May 2012

    SQL injection vulnerability in category_edit.php in Proman Xpress 5.0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:Vulnerability-Lab
    Published:13 Aug 2012
    4.3
    Medium

    CVE-2012-4262

    Last Modified: 7 May 2012

    Multiple cross-site scripting (XSS) vulnerabilities in myCare2x allow remote attackers to inject arbitrary web script or HTML via the (1) name_last, (2) name_first, (3) name_middle, or (4) name_maiden parameter to modules/patient/mycare_pid.php; (5) favorites or (6) lang parameter to modules/nursing/mycare_ward_print.php; (7) aktion or (8) callurl parameter to modules/patient/mycare2x_pat_info.php; or (9) ln parameter to modules/drg/mycare2x_proc_search.php.

    Source:Vulnerability-Lab
    Published:13 Aug 2012
    7.5
    High

    CVE-2012-4261

    Last Modified: 7 May 2012

    SQL injection vulnerability in modules/patient/mycare2x_pat_info.php in myCare2x allows remote attackers to execute arbitrary SQL commands via the lang parameter.

    Source:Vulnerability-Lab
    Published:13 Aug 2012
    7.5
    High

    CVE-2012-4260

    Last Modified: 7 May 2012

    Multiple SQL injection vulnerabilities in myCare2x allow remote attackers to execute arbitrary SQL commands via the (1) aktion or (2) callurl parameter to modules/patient/mycare2x_pat_info.php; (3) dept_nr or (4) pid parameter to modules/importer/mycare2x_importer.php; (5) myOpsEintrag or (6) keyword parameter in a Suchen action to modules/drg/mycare2x_proc_search.php; or (7) name_last or (8) pid parameter to modules/patient/mycare_pid.php.

    Source:Vulnerability-Lab
    Published:13 Aug 2012
    4.3
    Medium

    CVE-2012-4259

    Last Modified: 30 Apr 2012

    Cross-site scripting (XSS) vulnerability in the contacts in (1) XPhone UC Web and the (2) web frontend for XPhone Virtual Directory in C4B XPhone Unified Communications (UC) 2011 Web 4.1.890S R1 allows remote attackers to inject arbitrary web script or HTML via the company name. NOTE: some of these details are obtained from third party information.

    Source:Vulnerability-Lab
    Published:13 Aug 2012
    7.5
    High

    CVE-2012-4258

    Last Modified: 14 Jun 2012

    Multiple SQL injection vulnerabilities in MYRE Real Estate Software (2012 Q2) allow remote attackers to execute arbitrary SQL commands via the (1) link_idd parameter to 1_mobile/listings.php or (2) userid parameter to 1_mobile/agentprofile.php.

    Source:Vulnerability-Lab
    Published:13 Aug 2012
    4.3
    Medium

    CVE-2012-4254

    Last Modified: 27 May 2015

    MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/cubemail/restore.php or (2) learn/cubemail/dump.php.

    Source:AkaStep
    Published:13 Aug 2012
    4.3
    Medium

    CVE-2012-4253

    Last Modified: 27 May 2015

    Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to learn/cubemail/install.php or (2) f parameter learn/cubemail/filemanagement.php, or execute arbitrary local files via a .. (dot dot) in the (3) config parameter to learn/cubemail/menu.php.

    Source:AkaStep
    Published:13 Aug 2012
    5.1
    Medium

    CVE-2012-4252

    Last Modified: 27 May 2015

    Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of administrators for requests that (1) remove file access restriction via a deletehtaccess action, (2) drop a database via a kill value in a db action, (3) uninstall the application via a 101 value in the phase parameter to learn/cubemail/install.php, (4) delete config.php via a 2 value in the phase parameter to learn/cubemail/install.php, (5) change a password via a schutz action, or (6) execute arbitrary SQL commands via the sql_statement parameter to learn/cubemail/sql.php.

    Source:AkaStep
    Published:13 Aug 2012
    4.3
    Medium

    CVE-2012-4251

    Last Modified: 27 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3) tablename or (4) dbid parameter to sql.php, or (5) filename parameter to restore.php in learn/cubemail/.

    Source:AkaStep
    Published:13 Aug 2012
    9.3
    Critical

    CVE-2012-4250

    Last Modified: 1 May 2012

    Stack-based buffer overflow in the RequestScreenOptimization function in the XProcessControl.ocx ActiveX control in msls31.dll in Samsung NET-i viewer 1.37 allows remote attackers to execute arbitrary code via a long string in the first argument.

    Source:blake
    Published:13 Aug 2012
    4.3
    Medium

    CVE-2012-4247

    Last Modified: 16 Mar 2012

    Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) remote_user, (2) remote_database, (3) remote_userprefix, (4) remote_password, or (5) remote_prefix parameter to the import4 page; or the (6) id parameter to the bouncerule page.

    Source:Cyber-Crystal
    Published:12 Aug 2012
    4.3
    Medium

    CVE-2012-4246

    Last Modified: 16 Mar 2012

    Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter; or the (2) footer, (3) status, or (4) testtarget parameter in the send page.

    Source:Cyber-Crystal
    Published:12 Aug 2012
    4.3
    Medium

    CVE-2012-4242

    Last Modified: 19 Aug 2015

    Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar page.

    Source:Chris Cooper
    Published:1 Oct 2012
    6.5
    Medium

    CVE-2012-4240

    Last Modified: 4 Sept 2012

    SQL injection vulnerability in modules/calendar/json.php in Group-Office community before 4.0.90 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter.

    Source:Chris Cooper
    Published:11 Sept 2014
    6.8
    Medium

    CVE-2012-4237

    Last Modified: 13 Jul 2015

    Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the subject_module_id parameter to (1) tce_edit_answer.php or (2) tce_edit_question.php.

    Source:Chris Cooper
    Published:20 Aug 2012
    4.3
    Medium

    CVE-2012-4236

    Last Modified: 18 Jul 2015

    Cross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK eCommerce Open Source before 2.1.2_p1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:Chris Cooper
    Published:20 Aug 2012
    4.3
    Medium

    CVE-2012-4234

    Last Modified: 24 Jul 2015

    Cross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via the group parameter.

    Source:High-Tech Bridge
    Published:4 Sept 2014
    4.3
    Medium

    CVE-2012-4231

    Last Modified: 24 Aug 2015

    Cross-site scripting (XSS) vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to inject arbitrary web script or HTML via the path parameter.

    Source:High-Tech Bridge
    Published:22 Oct 2012
    6.8
    Medium

    CVE-2012-4220

    Last Modified: 11 Apr 2025

    diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via an application that uses crafted arguments in a local diagchar_ioctl call.

    Published:30 Nov 2012
    7.5
    High

    CVE-2012-4178

    Last Modified: 30 Jul 2012

    SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid parameter.

    Source:Kc57
    Published:7 Aug 2012
    10
    Critical

    CVE-2012-4177

    Last Modified: 8 Aug 2012

    The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line argument.

    Source:Metasploit
    Published:7 Aug 2012
    9.3
    Critical

    CVE-2012-4170

    Last Modified: 1 Sept 2012

    Buffer overflow in Adobe Photoshop CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafted file.

    Source:Francis Provencher
    Published:31 Aug 2012
    7.5
    High

    CVE-2012-4070

    Last Modified: 13 Jul 2015

    SQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote attackers to execute arbitrary SQL commands via the oid parameter in a homepage action to index.php.

    Source:Daniel Correa
    Published:12 Aug 2012
    7.5
    High

    CVE-2012-4060

    Last Modified: 26 May 2015

    Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) profile.asp, (2) forum.asp, or (3) topic.asp.

    Source:Farbod Mahini
    Published:25 Jul 2012
    9.3
    Critical

    CVE-2012-4057

    Last Modified: 13 Aug 2012

    Buffer overflow in the Player in Remote-Anything 5.60.15 allows remote attackers to execute arbitrary code via a crafted flm file.

    Source:Saint Patrick
    Published:25 Jul 2012
    7.5
    High

    CVE-2012-4055

    Last Modified: 26 May 2015

    SQL injection vulnerability in index2.php in Uiga Fan Club allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Source:Farbod Mahini
    Published:25 Jul 2012
    6.9
    Medium

    CVE-2012-4054

    Last Modified: 29 Apr 2012

    Buffer overflow in the readfile function in CPE17 Autorun Killer 1.7.1 and earlier allows physically proximate attackers to execute arbitrary code via a crafted inf file.

    Source:Xenithz xpt
    Published:25 Jul 2012
    6.8
    Medium

    CVE-2012-4051

    Last Modified: 27 Sept 2012

    Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Suite before 8.61 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts or (2) change passwords via a Save action.

    Source:Jacob Holcomb
    Published:28 Sept 2012
    6.8
    Medium

    CVE-2012-4036

    Last Modified: 14 Jul 2015

    Unrestricted file upload vulnerability in admin.php in PBBoard 2.1.4 allows remote administrators to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the addons directory. NOTE: this vulnerability can be leveraged by remote attackers using CVE-2012-1216.

    Source:High-Tech Bridge
    Published:27 Aug 2012
    7.5
    High

    CVE-2012-4035

    Last Modified: 14 Jul 2015

    The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password parameters to index.php.

    Source:High-Tech Bridge
    Published:12 Aug 2012
    7.5
    High

    CVE-2012-4034

    Last Modified: 14 Jul 2015

    Multiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to the send page, (2) email parameter to the forget page, (3) password parameter to the forum_archive page, (4) section parameter to the management page, (5) section_id parameter to the managementreply page, (6) member_id parameter to the new_password page, or (7) subjectid parameter to the tags page to index.php.

    Source:High-Tech Bridge
    Published:12 Aug 2012
    5.8
    Medium

    CVE-2012-4032

    Last Modified: 17 Aug 2017

    Open redirect vulnerability in the login page in WebsitePanel before 1.2.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in ReturnUrl to Default.aspx.

    Source:Anastasios Monachos
    Published:17 Jul 2012
    5
    Medium

    CVE-2012-4031

    Last Modified: 2 Jul 2012

    Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) lang or (2) langid cookie to port 85.

    Source:Dillon Beresford
    Published:17 Jul 2012