7.2
    High

    CVE-2012-2957

    Last Modified: 19 Jul 2017

    The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue.

    Source:muts
    Published:23 Jul 2012
    6.5
    Medium

    CVE-2012-2956

    Last Modified: 23 Jul 2012

    SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v2.json. NOTE: this entry was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6658 is for the XSS.

    Source:dookie
    Published:17 Sept 2014
    4.3
    Medium

    CVE-2012-2955

    Last Modified: 8 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allow remote attackers to inject arbitrary web script or HTML via the query string.

    Source:muts
    Published:20 Jul 2012
    10
    Critical

    CVE-2012-2953

    Last Modified: 27 Jul 2012

    The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.

    Source:Metasploit
    Published:23 Jul 2012
    7.5
    High

    CVE-2012-2952

    Last Modified: 24 May 2012

    SQL injection vulnerability in add_ons.php in Jaow 2.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the add_ons parameter.

    Source:kallimero
    Published:29 May 2012
    4.3
    Medium

    CVE-2012-2941

    Last Modified: 7 Jun 2015

    Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server 2010 9.0 Enterprise allows remote attackers to inject arbitrary web script or HTML via the text parameter.

    Source:MustLive
    Published:27 May 2012
    4.3
    Medium

    CVE-2012-2940

    Last Modified: 21 May 2012

    MediaChance Real-DRAW PRO 5.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted (1) PNG, (2) WMF, (3) PSD, (4) TGA, (5) TTF, (6) BMP, (7) TIFF, or (8) PCX file.

    Source:Ahmed Elhady Mohamed
    Published:27 May 2012
    6.5
    Medium

    CVE-2012-2939

    Last Modified: 13 May 2012

    Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) airline-edit.php, (2) hotel-image-add.php, or (3) hotel-add.php.

    Source:Vulnerability-Lab
    Published:27 May 2012
    4.3
    Medium

    CVE-2012-2938

    Last Modified: 13 May 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the holiday name field to (1) holiday_add.php or (2) holiday_view.php.

    Source:Vulnerability-Lab
    Published:27 May 2012
    9.1
    Critical

    CVE-2012-2926

    Last Modified: 6 Jun 2015

    Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.

    Source:anonymous
    Published:22 May 2012
    7.5
    High

    CVE-2012-2925

    Last Modified: 9 May 2012

    SQL injection vulnerability in engine.php in Simple PHP Agenda 2.2.8 allows remote attackers to execute arbitrary SQL commands via the priority parameter in an addTodo action.

    Source:loneferret
    Published:21 May 2012
    7.5
    High

    CVE-2012-2924

    Last Modified: 10 May 2012

    PHP remote file inclusion vulnerability in admin/setup.inc.php in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:Andrey Komarov
    Published:21 May 2012
    7.5
    High

    CVE-2012-2923

    Last Modified: 10 May 2012

    SQL injection vulnerability in news.php4 in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary SQL commands via the nid parameter.

    Source:Andrey Komarov
    Published:21 May 2012
    5
    Medium

    CVE-2012-2919

    Last Modified: 29 May 2015

    Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the v parameter.

    Source:AkaStep
    Published:21 May 2012
    4.3
    Medium

    CVE-2012-2918

    Last Modified: 29 May 2015

    Cross-site scripting (XSS) vulnerability in Upload/engine.php in Chevereto 1.91 allows remote attackers to inject arbitrary web script or HTML via the v parameter.

    Source:AkaStep
    Published:21 May 2012
    4.3
    Medium

    CVE-2012-2917

    Last Modified: 5 Jun 2015

    Cross-site scripting (XSS) vulnerability in the Share and Follow plugin 1.80.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the CDN API Key (cnd-key) in a share-and-follow-menu page to wp-admin/admin.php.

    Source:Heine Pedersen
    Published:21 May 2012
    9.3
    Critical

    CVE-2012-2915

    Last Modified: 16 Nov 2017

    Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary code via a long string in a Value tag in a SymbolicSchematicData definition tag in PAC Design (.pac) file.

    Source:b33f
    Published:21 May 2012
    4.3
    Medium

    CVE-2012-2914

    Last Modified: 6 Jun 2015

    Cross-site scripting (XSS) vulnerability in captchademo.php in Unijimpe Captcha allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:Daniel Godoy
    Published:21 May 2012
    4.3
    Medium

    CVE-2012-2913

    Last Modified: 4 Jun 2015

    Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin 0.0.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) leaflet_layer.php or (2) leaflet_marker.php, as reachable through wp-admin/admin.php.

    Source:Heine Pedersen
    Published:21 May 2012
    4.3
    Medium

    CVE-2012-2911

    Last Modified: 5 Jun 2015

    Cross-site scripting (XSS) vulnerability in backupDB.php in SiliSoftware backupDB() 1.2.7a allows remote attackers to inject arbitrary web script or HTML via the onlyDB parameter.

    Source:LiquidWorm
    Published:21 May 2012
    4.3
    Medium

    CVE-2012-2910

    Last Modified: 5 Jun 2015

    Multiple cross-site scripting (XSS) vulnerabilities in SiliSoftware phpThumb() 1.7.11 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter to demo/phpThumb.demo.random.php or (2) title parameter to demo/phpThumb.demo.showpic.php.

    Source:Gjoko Krstic
    Published:21 May 2012
    4.3
    Medium

    CVE-2012-2909

    Last Modified: 13 May 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Viscacha 0.8.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) text field in the Private Messages System, (2) Bad Word field in Zensur, or (3) Portal or (4) Topic field in Kommentar.

    Source:Vulnerability-Lab
    Published:21 May 2012
    7.5
    High

    CVE-2012-2908

    Last Modified: 13 May 2012

    Multiple SQL injection vulnerabilities in admin/bbcodes.php in Viscacha 0.8.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) bbcodeexample, (2) buttonimage, or (3) bbcodetag parameter.

    Source:Vulnerability-Lab
    Published:21 May 2012
    4.3
    Medium

    CVE-2012-2906

    Last Modified: 6 Jun 2015

    Multiple cross-site scripting (XSS) vulnerabilities in artpublic/recommandation/index.php in Artiphp CMS 5.5.0 Neo (r422) allow remote attackers to inject arbitrary web script or HTML via the (1) add_img_name_post, (2) asciiart_post, (3) expediteur, (4) titre_sav, or (5) z39d27af885b32758ac0e7d4014a61561 parameter.

    Source:Gjoko Krstic
    Published:21 May 2012
    5
    Medium

    CVE-2012-2905

    Last Modified: 16 May 2012

    Artiphp CMS 5.5.0 Neo (r422) stores database backups with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.

    Source:LiquidWorm
    Published:21 May 2012
    4.3
    Medium

    CVE-2012-2904

    Last Modified: 5 Jun 2015

    player.swf in LongTail JW Player 5.9 allows remote attackers to conduct cross-site scripting (XSS) attacks to inject arbitrary web script or HTML via multiple "javascript:" sequences in the debug parameter.

    Source:gainover
    Published:21 May 2012
    4.3
    Medium

    CVE-2012-2903

    Last Modified: 18 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 7.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to group.php, or the (2) target_language or (3) target_flag parameter to translate.php.

    Source:Stefan Schurtz
    Published:21 May 2012
    Unknown

    CVE-2012-2765

    https://www.exploit-db.com/exploits/17349

    7.2
    High

    CVE-2012-2764

    Last Modified: 15 Nov 2017

    Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain privileges via a Trojan horse Metro DLL in the current working directory.

    Source:Moshe Zioni
    Published:27 Jun 2012
    7.5
    High

    CVE-2012-2763

    Last Modified: 7 Mar 2019

    Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

    Source:Joseph Sheridan
    Published:30 May 2012
    2.1
    Low

    CVE-2012-2760

    Last Modified: 31 Jan 2017

    mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.

    Source:Peter Ellehauge
    Published:25 Jul 2012
    4.3
    Medium

    CVE-2012-2741

    Last Modified: 16 Nov 2012

    Cross-site scripting (XSS) vulnerability in public_html/lists/admin/ in phpList before 2.10.18 allows remote attackers to inject arbitrary web script or HTML via the num parameter in a reconcileusers action.

    Source:LiquidWorm
    Published:6 Sept 2012
    7.5
    High

    CVE-2012-2740

    Last Modified: 16 Nov 2012

    SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbitrary SQL commands via the sortby parameter in a find action.

    Source:LiquidWorm
    Published:6 Sept 2012
    4
    Medium

    CVE-2012-2738

    Last Modified: 4 Jul 2015

    The VteTerminal in gnome-terminal (vte) before 0.32.2 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.

    Source:Kevin Fenzi
    Published:15 May 2012
    4.3
    Medium

    CVE-2012-2698

    Last Modified: 27 Jun 2015

    Cross-site scripting (XSS) vulnerability in the outputPage function in includes/SkinTemplate.php in MediaWiki before 1.17.5, 1.18.x before 1.18.4, and 1.19.x before 1.19.1 allows remote attackers to inject arbitrary web script or HTML via the uselang parameter to index.php/Main_page.

    Source:anonymous
    Published:29 Jun 2012
    10
    Critical

    CVE-2012-2688

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

    Published:19 Jul 2012
    5
    Medium

    CVE-2012-2661

    Last Modified: 11 Apr 2025

    The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that leverage unintended recursion, a related issue to CVE-2012-2695.

    Published:31 May 2012
    8.8
    High

    CVE-2012-2629

    Last Modified: 16 May 2012

    Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator account via an addnew action to admin/administrators_add.php; or (2) conduct cross-site scripting (XSS) attacks via the page_title parameter to admin/content_pages_edit.php; the (3) category_name[] parameter to admin/products_category.php; the (4) site_name, (5) seo_title, or (6) meta_keywords parameter to admin/settings_siteinfo.php; the (7) company_name, (8) address1, (9) address2, (10) city, (11) state, (12) country, (13) author_first_name, (14) author_last_name, (15) author_email, (16) contact_first_name, (17) contact_last_name, (18) contact_email, (19) general_email, (20) general_phone, (21) general_fax, (22) sales_email, (23) sales_phone, (24) support_email, or (25) support_phone parameter to admin/settings_company.php; or the (26) system_email, (27) sender_name, (28) smtp_server, (29) smtp_username, (30) smtp_password, or (31) order_notice_email parameter to admin/settings_email.php.

    Source:Ivano Binetti
    Published:20 Feb 2020
    9.4
    Critical

    CVE-2012-2627

    Last Modified: 10 Jul 2015

    d4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrite arbitrary files in %PROGRAMFILES%\Scrutinizer\snmp\mibs\ via a multipart/form-data POST request.

    Source:Mario Ceballos
    Published:31 Jul 2012
    5
    Medium

    CVE-2012-2626

    Last Modified: 10 Jul 2015

    cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action.

    Source:Mario Ceballos
    Published:31 Jul 2012
    7.8
    High

    CVE-2012-2619

    Last Modified: 22 Dec 2017

    The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Motorola, Nokia, Pantech, Samsung, and Sony products, allow remote attackers to cause a denial of service (out-of-bounds read and Wi-Fi outage) via an RSN 802.11i information element.

    Source:CoreLabs
    Published:14 Nov 2012
    6.8
    Medium

    CVE-2012-2614

    Last Modified: 22 Jun 2012

    Buffer overflow in programmer.exe in Lattice Diamond Programmer 1.4.2 allows user-assisted remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long string in a version attribute of an ispXCF element in an .xcf file.

    Source:Core Security
    Published:12 Jul 2012
    5
    Medium

    CVE-2012-2612

    Last Modified: 27 Oct 2016

    The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

    Source:Core Security
    Published:15 May 2012
    9.3
    Critical

    CVE-2012-2611

    Last Modified: 27 Oct 2016

    The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execute arbitrary code via a crafted SAP Diag packet.

    Source:Core Security
    Published:15 May 2012
    6.8
    Medium

    CVE-2012-2602

    Last Modified: 25 May 2017

    Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to Admin/Accounts/Add/OrionAccount.aspx or (2) modify account privileges via a ynAdminRights action to Admin/Accounts/EditAccount.aspx.

    Source:muts
    Published:12 Aug 2012
    7.5
    High

    CVE-2012-2601

    Last Modified: 22 Jul 2012

    SQL injection vulnerability in WrVMwareHostList.asp in Ipswitch WhatsUp Gold 15.02 allows remote attackers to execute arbitrary SQL commands via the sGroupList parameter.

    Source:muts
    Published:15 Aug 2012
    Low

    CVE-2012-2599

    Last Modified: 18 Dec 2016

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-3835. Reason: This issue was MERGED into CVE-2012-3835 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2012-3835 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Stefan Schurtz
    Published:20 Feb 2020
    6.1
    Medium

    CVE-2012-2593

    Last Modified: 21 Jul 2012

    Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email.

    Source:muts
    Published:6 Feb 2020
    4.3
    Medium

    CVE-2012-2592

    Last Modified: 8 Aug 2012

    Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email.

    Source:loneferret
    Published:18 Jun 2014
    4.3
    Medium

    CVE-2012-2591

    Last Modified: 8 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) From or (2) Date field in an email.

    Source:loneferret
    Published:20 Jun 2014