4.3
    Medium

    CVE-2012-2590

    Last Modified: 8 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in ESCON SupportPortal Professional Edition 3.0 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted SRC attribute of an IFRAME element, (3) a crafted CONTENT attribute of an HTTP-EQUIV="Set-Cookie" META element, or (4) an innerHTML attribute within an XML document.

    Source:loneferret
    Published:12 Aug 2012
    Low

    CVE-2012-2589

    Last Modified: 22 Jul 2012

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-4344. Reason: This candidate is a duplicate of CVE-2012-4344. Notes: All CVE users should reference CVE-2012-4344 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:muts
    Published:20 Nov 2012
    4.3
    Medium

    CVE-2012-2588

    Last Modified: 8 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message.

    Source:loneferret
    Published:19 Sept 2014
    4.3
    Medium

    CVE-2012-2587

    Last Modified: 8 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in AfterLogic MailSuite Pro 6.3 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with a crafted SRC attribute of (1) an IFRAME element or (2) a SCRIPT element.

    Source:loneferret
    Published:12 Aug 2012
    4.3
    Medium

    CVE-2012-2586

    Last Modified: 8 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary web script or HTML via an e-mail message subject with (1) a JavaScript alert function used in conjunction with the fromCharCode method or (2) a SCRIPT element; an e-mail message body with (3) a crafted SRC attribute of an IFRAME element, (4) a data: URL in the CONTENT attribute of an HTTP-EQUIV="refresh" META element, or (5) a Cascading Style Sheets (CSS) expression property in the STYLE attribute of an IMG element; or an e-mail message Date header with (6) a JavaScript alert function used in conjunction with the fromCharCode method, (7) a SCRIPT element, (8) a CSS expression property in the STYLE attribute of an arbitrary element, (9) a crafted SRC attribute of an IFRAME element, or (10) a data: URL in the CONTENT attribute of an HTTP-EQUIV="refresh" META element.

    Source:loneferret
    Published:19 Sept 2012
    4.3
    Medium

    CVE-2012-2585

    Last Modified: 8 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression property, (3) a CSS expression property in the STYLE attribute of an arbitrary element, or (4) a crafted SRC attribute of an IFRAME element, or an e-mail message subject with (5) a SCRIPT element, (6) a CSS expression property in the STYLE attribute of an arbitrary element, (7) a crafted SRC attribute of an IFRAME element, (8) a crafted CONTENT attribute of an HTTP-EQUIV="refresh" META element, or (9) a data: URL in the CONTENT attribute of an HTTP-EQUIV="refresh" META element.

    Source:loneferret
    Published:12 Aug 2012
    4.3
    Medium

    CVE-2012-2584

    Last Modified: 5 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) the Cascading Style Sheets (CSS) expression property in conjunction with a CSS comment within the STYLE attribute of an IMG element, (2) the CSS expression property in conjunction with multiple CSS comments within the STYLE attribute of an arbitrary element, or (3) an innerHTML attribute within an XML document.

    Source:loneferret
    Published:12 Aug 2012
    4.3
    Medium

    CVE-2012-2583

    Last Modified: 8 Aug 2012

    Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web script or HTML via the body of an email.

    Source:loneferret
    Published:17 Sept 2014
    4.3
    Medium

    CVE-2012-2582

    Last Modified: 8 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before 3.0.15, and 3.1.x before 3.1.9, and OTRS ITSM 2.1.x before 2.1.5, 3.0.x before 3.0.6, and 3.1.x before 3.1.6, allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a Cascading Style Sheets (CSS) expression property in the STYLE attribute of an arbitrary element or (2) UTF-7 text in an HTTP-EQUIV="CONTENT-TYPE" META element.

    Source:loneferret
    Published:23 Aug 2012
    4.3
    Medium

    CVE-2012-2580

    Last Modified: 8 Aug 2012

    Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbitrary web script or HTML via the From field of an email.

    Source:loneferret
    Published:20 Jun 2014
    4.3
    Medium

    CVE-2012-2579

    Last Modified: 8 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) To, (2) From, (3) Date, or (4) Subject field of an email.

    Source:loneferret
    Published:20 Jun 2014
    4.3
    Medium

    CVE-2012-2578

    Last Modified: 8 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a JavaScript alert function used in conjunction with the fromCharCode method, (2) a SCRIPT element, (3) a Cascading Style Sheets (CSS) expression property in the STYLE attribute of an arbitrary element, or (4) an innerHTML attribute within an XML document.

    Source:loneferret
    Published:19 Sept 2012
    4.3
    Medium

    CVE-2012-2577

    Last Modified: 25 May 2017

    Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf file.

    Source:muts
    Published:12 Aug 2012
    9.8
    Critical

    CVE-2012-2576

    Last Modified: 1 May 2012

    SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.

    Source:muts
    Published:20 Dec 2017
    4.3
    Medium

    CVE-2012-2575

    Last Modified: 8 Aug 2012

    Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 6.0a4 allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IFRAME element in the body of an HTML e-mail message.

    Source:loneferret
    Published:17 Sept 2012
    7.5
    High

    CVE-2012-2574

    Last Modified: 23 Jul 2012

    SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to a "blind SQL injection" issue.

    Source:muts
    Published:23 Jul 2012
    4.3
    Medium

    CVE-2012-2573

    Last Modified: 27 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in T-dah WebMail 3.2.0-2.3 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression property, (3) a CSS expression property in the STYLE attribute of an arbitrary element, (4) an ONLOAD attribute of a BODY element, (5) a crafted SRC attribute of an IFRAME element, (6) a crafted CONTENT attribute of an HTTP-EQUIV="refresh" META element, or (7) a data: URL in the CONTENT attribute of an HTTP-EQUIV="refresh" META element.

    Source:Shai rod
    Published:12 Aug 2012
    4.3
    Medium

    CVE-2012-2572

    Last Modified: 8 Aug 2012

    Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Subject of an email.

    Source:loneferret
    Published:19 Jun 2014
    4.3
    Medium

    CVE-2012-2571

    Last Modified: 8 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in WinWebMail Server 3.8.1.6 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression property, (3) a CSS expression property in the STYLE attribute of an arbitrary element, (4) a crafted SRC attribute of an IFRAME element, or (5) UTF-7 text in an HTTP-EQUIV="CONTENT-TYPE" META element.

    Source:loneferret
    Published:12 Aug 2012
    4.3
    Medium

    CVE-2012-2570

    Last Modified: 8 Jul 2015

    Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote attackers to inject arbitrary web script or HTML via the symb parameter.

    Source:Am!r
    Published:15 Aug 2012
    4.3
    Medium

    CVE-2012-2569

    Last Modified: 8 Aug 2012

    Cross-site scripting (XSS) vulnerability in Synametrics Technologies Xeams 4.4 Build 5720 allows remote attackers to inject arbitrary web script or HTML via the body of an email.

    Source:loneferret
    Published:19 Jun 2014
    6.1
    Medium

    CVE-2012-2517

    Last Modified: 24 Jul 2015

    Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.

    Source:High-Tech Bridge
    Published:11 Feb 2020
    9.3
    Critical

    CVE-2012-2516

    Last Modified: 11 Oct 2012

    An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows remote attackers to execute arbitrary commands via crafted input, related to a "command injection vulnerability."

    Source:Metasploit
    Published:5 Jul 2012
    5
    Medium

    CVE-2012-2514

    Last Modified: 27 Oct 2016

    The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

    Source:Core Security
    Published:15 May 2012
    5
    Medium

    CVE-2012-2513

    Last Modified: 27 Oct 2016

    The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

    Source:Core Security
    Published:15 May 2012
    5
    Medium

    CVE-2012-2512

    Last Modified: 27 Oct 2016

    The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

    Source:Core Security
    Published:15 May 2012
    5
    Medium

    CVE-2012-2511

    Last Modified: 27 Oct 2016

    The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

    Source:Core Security
    Published:15 May 2012
    5
    Medium

    CVE-2012-2459

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in bitcoind and Bitcoin-Qt before 0.4.6, 0.5.x before 0.5.5, 0.6.0.x before 0.6.0.7, and 0.6.x before 0.6.2 allows remote attackers to cause a denial of service (block-processing outage and incorrect block count) via unknown behavior on a Bitcoin network.

    Published:6 Aug 2012
    6.1
    Medium

    CVE-2012-2452

    Last Modified: 19 Jun 2015

    Multiple cross-site scripting (XSS) vulnerabilities in pragmaMx 1.x before 1.12.2 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to modules.php or (2) img_url to includes/wysiwyg/spaw/editor/plugins/imgpopup/img_popup.php.

    Source:High-Tech Bridge SA
    Published:11 Feb 2020
    4.3
    Medium

    CVE-2012-2442

    Last Modified: 27 Apr 2012

    Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial of service via a crafted mp4 file.

    Source:Senator of Pirates
    Published:25 Jul 2012
    8.5
    High

    CVE-2012-2441

    Last Modified: 24 Apr 2012

    RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) SSH or (2) HTTPS session, a different vulnerability than CVE-2012-1803.

    Source:jc
    Published:28 Apr 2012
    5
    Medium

    CVE-2012-2437

    Last Modified: 20 Oct 2017

    cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.

    Source:Sooel Son
    Published:26 Nov 2012
    4.3
    Medium

    CVE-2012-2436

    Last Modified: 24 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter in a move or (2) minimize action to admin/admin_index.php; (3) the karma_username parameter to module.php in the karma module; (4) q_1_low, (5) q_1_high, (6) q_2_low, or (7) q_2_high parameter in a configure action to module.php in the captcha module; or (8) the edit parameter to module.php in the admin_language module.

    Source:High-Tech Bridge SA
    Published:27 May 2012
    4.3
    Medium

    CVE-2012-2396

    Last Modified: 23 Nov 2016

    VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted MP4 file.

    Source:Senator of Pirates
    Published:19 Apr 2012
    3.3
    Low

    CVE-2012-2394

    Last Modified: 12 Nov 2016

    Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 on the SPARC and Itanium platforms does not properly perform data alignment for a certain structure member, which allows remote attackers to cause a denial of service (application crash) via a (1) ICMP or (2) ICMPv6 Echo Request packet.

    Source:Klaus Heckelmann
    Published:21 May 2012
    3.3
    Low

    CVE-2012-2393

    Last Modified: 12 Nov 2016

    epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 does not properly construct certain array data structures, which allows remote attackers to cause a denial of service (application crash) via a crafted packet that triggers incorrect memory allocation.

    Source:Wireshark
    Published:21 May 2012
    3.3
    Low

    CVE-2012-2392

    Last Modified: 12 Nov 2016

    Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allows remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) ANSI MAP, (2) ASF, (3) IEEE 802.11, (4) IEEE 802.3, and (5) LTP dissectors.

    Source:Laurent Butti
    Published:21 May 2012
    7.5
    High

    CVE-2012-2386

    Last Modified: 22 Apr 2015

    Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.

    Source:Alexander Gavrun
    Published:21 May 2012
    4
    Medium

    CVE-2012-2385

    Last Modified: 19 Jun 2015

    The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.

    Source:Timo Juhani Lindfors
    Published:29 Jun 2012
    10
    Critical

    CVE-2012-2376

    Last Modified: 31 Jan 2017

    Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.

    Source:0in
    Published:19 May 2012
    4.3
    Medium

    CVE-2012-2371

    Last Modified: 1 Jun 2015

    Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pagination_wp_facethumb parameter.

    Source:d3v1l
    Published:13 Aug 2012
    Low

    CVE-2012-2344

    Last Modified: 29 Dec 2010

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-5099. Reason: This candidate is a duplicate of CVE-2010-5099. Notes: All CVE users should reference CVE-2010-5099 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:ikki
    Published:21 May 2012
    7.5
    High

    CVE-2012-2338

    Last Modified: 12 Nov 2016

    SQL injection vulnerability in includes/picture.class.php in Galette 0.63, 0.63.1, 0.63.2, 0.63.3, and 0.64rc1 allows remote attackers to execute arbitrary SQL commands via the id_adh parameter to picture.php.

    Source:sbz
    Published:21 May 2012
    5
    Medium

    CVE-2012-2336

    Last Modified: 16 May 2014

    sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'T' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.

    Source:kingcope
    Published:3 May 2012
    7.5
    High

    CVE-2012-2332

    Last Modified: 31 Oct 2016

    SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[plugin_to_conf] parameter. NOTE: this issue might be resultant from cross-site request forgery (CSRF).

    Source:Stefan Schurtz
    Published:13 Aug 2012
    4.3
    Medium

    CVE-2012-2331

    Last Modified: 31 Oct 2016

    Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the serendipity[textarea] parameter. NOTE: this issue might be resultant from cross-site request forgery (CSRF).

    Source:Stefan Schurtz
    Published:13 Aug 2012
    5
    Medium

    CVE-2012-2329

    Last Modified: 1 Dec 2016

    Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.

    Source:Metasploit
    Published:8 May 2012
    6.8
    Medium

    CVE-2012-2316

    Last Modified: 16 May 2012

    Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary code via the script parameter to admin/scripting.jsp.

    Source:Cyrill Brunschwiler
    Published:9 Sept 2012
    4
    Medium

    CVE-2012-2315

    Last Modified: 16 May 2012

    admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.

    Source:Cyrill Brunschwiler
    Published:9 Sept 2012
    7.5
    High

    CVE-2012-2311

    Last Modified: 16 May 2014

    sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.

    Source:kingcope
    Published:3 May 2012