4.3
    Medium

    CVE-2012-1556

    Last Modified: 8 May 2015

    Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to photo/photo_one.php.

    Source:Simon Ganiere
    Published:12 Sept 2014
    7.8
    High

    CVE-2012-1535

    Last Modified: 28 Aug 2012

    Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploited in the wild in August 2012 with SWF content in a Word document.

    Source:Metasploit
    Published:14 Aug 2012
    10
    Critical

    CVE-2012-1533

    Last Modified: 11 Jun 2013

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-3159.

    Source:Rh0
    Published:16 Oct 2012
    4.3
    Medium

    CVE-2012-1507

    Last Modified: 29 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plugins/ajaxCalls/haltResumeHsp.php, (2) sortOrder1 parameter to templates/hrfunct/emppop.php, or (3) uri parameter to index.php.

    Source:High-Tech Bridge SA
    Published:17 Sept 2014
    6.5
    Medium

    CVE-2012-1506

    Last Modified: 29 May 2015

    SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php. NOTE: some of these details are obtained from third party information.

    Source:High-Tech Bridge SA
    Published:17 Sept 2014
    4.3
    Medium

    CVE-2012-1503

    Last Modified: 22 Oct 2012

    Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.

    Source:sqlhacker
    Published:29 Aug 2014
    7.5
    High

    CVE-2012-1502

    Last Modified: 10 Mar 2012

    Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.

    Source:Markus Vervier
    Published:8 Mar 2012
    5.4
    Medium

    CVE-2012-1500

    Last Modified: 4 Sept 2012

    Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.

    Source:Hoyt LLC Research
    Published:13 Feb 2020
    6.8
    Medium

    CVE-2012-1498

    Last Modified: 29 Feb 2012

    Multiple cross-site request forgery (CSRF) vulnerabilities in Webfolio CMS 1.1.4 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via an add action to admin/users/add or (2) modify a web page via a save action to admin/pages/edit/web_page_name.

    Source:Ivano Binetti
    Published:19 Mar 2012
    8.8
    High

    CVE-2012-1496

    Last Modified: 8 Dec 2016

    Local file inclusion in WebCalendar before 1.2.5.

    Source:EgiX
    Published:27 Jan 2020
    9.8
    Critical

    CVE-2012-1495

    Last Modified: 9 Dec 2016

    install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.

    Source:Metasploit
    Published:27 Jan 2020
    7.8
    High

    CVE-2012-1493

    Last Modified: 9 Dec 2016

    F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.

    Source:Florent Daigniere
    Published:9 Jul 2012
    4.3
    Medium

    CVE-2012-1470

    Last Modified: 16 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in code_editor.php in ocPortal before 7.1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) path or (2) line parameters.

    Source:High-Tech Bridge
    Published:1 Oct 2012
    4.3
    Medium

    CVE-2012-1469

    Last Modified: 13 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remote authenticated users to inject arbitrary web script or HTML via the (1) editor or (2) callback parameters to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/ibrowser.php in the iBrowser plugin, (3) authors[][url] parameter to index.php, or (4) Bio Statement or (5) Abstract of Submission fields to the stripUnsafeHtml function in lib/pkp/classes/core/String.inc.php.

    Source:High-Tech Bridge
    Published:6 Sept 2012
    6
    Medium

    CVE-2012-1468

    Last Modified: 13 May 2015

    Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Role permission to execute arbitrary code by uploading a file with an executable extension that is not ".php", then accessing it via a direct request to the file in submission/original/ in the associated article directory, as demonstrated using .pHp, .asp, and other extensions.

    Source:High-Tech Bridge
    Published:6 Sept 2012
    6.5
    Medium

    CVE-2012-1467

    Last Modified: 5 Jan 2017

    Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.7, allow remote authenticated users to (1) delete or (2) rename arbitrary files via a .. (dot dot) in the param parameter to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/scripts/rfiles.php.

    Source:High-Tech Bridge
    Published:6 Sept 2012
    5
    Medium

    CVE-2012-1466

    Last Modified: 29 Feb 2012

    The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with a .nd extension via an invalid version number in an HTTP request, as demonstrated using default.nd. NOTE: some of these details are obtained from third party information.

    Source:SecPod Research
    Published:19 Mar 2012
    4.3
    Medium

    CVE-2012-1465

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause a denial of service (application crash) via a long URL in an HTTP request. NOTE: some of these details are obtained from third party information.

    Source:SecPod Research
    Published:19 Mar 2012
    5
    Medium

    CVE-2012-1464

    Last Modified: 29 Feb 2012

    Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing "?" character, which causes Dashboard to attempt to access a non-existent resource. NOTE: some of these details are obtained from third party information.

    Source:SecPod Research
    Published:19 Mar 2012
    3.5
    Low

    CVE-2012-1417

    Last Modified: 29 Feb 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.

    Source:Narendra Shinde
    Published:17 Sept 2014
    6.8
    Medium

    CVE-2012-1416

    Last Modified: 16 Feb 2012

    Multiple cross-site request forgery (CSRF) vulnerabilities in SocialCMS 1.0.2 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrator accounts via a member_new action to my_admin/admin1_members.php or (2) modify the default site title via a save action to my_admin/admin1_configuration.php.

    Source:Ivano Binetti
    Published:8 Oct 2012
    6.8
    Medium

    CVE-2012-1415

    Last Modified: 16 Mar 2012

    Cross-site request forgery (CSRF) vulnerability in lib/logout.php in DFLabs PTK 1.0.5 and earlier allows remote attackers to hijack the authentication of administrators or investigators for requests that trigger a logout.

    Source:Ivano Binetti
    Published:28 Dec 2014
    6.8
    Medium

    CVE-2012-1414

    Last Modified: 16 Mar 2012

    Cross-site request forgery (CSRF) vulnerability in manager/news.php in Plume CMS 1.2.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that create News pages via a publish action.

    Source:Ivano Binetti
    Published:7 Oct 2012
    Unknown

    CVE-2012-1309

    https://www.exploit-db.com/exploits/18511

    6.8
    Medium

    CVE-2012-1308

    Last Modified: 24 Aug 2017

    Cross-site request forgery (CSRF) vulnerability in redpass.cgi in D-Link DSL-2640B Firmware EU_4.00 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.

    Source:Ivano Binetti
    Published:8 Oct 2012
    Unknown

    CVE-2012-1305

    https://www.exploit-db.com/exploits/18563

    Unknown

    CVE-2012-1304

    https://www.exploit-db.com/exploits/18483

    Unknown

    CVE-2012-1300

    https://www.exploit-db.com/exploits/18655

    6.8
    Medium

    CVE-2012-1297

    Last Modified: 27 Feb 2012

    Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via a delete action in the user module, (2) delete news via a delete action in the news module, or (3) delete newsletters via a delete action in the newsletters module.

    Source:Ivano Binetti
    Published:19 Mar 2012
    7.5
    High

    CVE-2012-1294

    Last Modified: 27 Apr 2015

    SQL injection vulnerability in CONTIMEX Impulsio CMS allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:sonyy
    Published:23 Feb 2012
    6.1
    Medium

    CVE-2012-1261

    Last Modified: 28 Jul 2012

    Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow and sFlow Analyzer 8.6.2.16204 and other versions before 9.0.1.19899 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter.

    Source:Trustwave's SpiderLabs
    Published:9 Jan 2020
    6.1
    Medium

    CVE-2012-1260

    Last Modified: 28 Jul 2012

    Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allows remote attackers to inject arbitrary web script or HTML via the newUser parameter. NOTE: this might not be a vulnerability, since an administrator might already have the privileges to create arbitrary script.

    Source:Trustwave's SpiderLabs
    Published:9 Jan 2020
    9.8
    Critical

    CVE-2012-1259

    Last Modified: 28 Jul 2012

    Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to cgi-bin/scrut_fa_exclusions.cgi, (2) getPermissionsAndPreferences parameter to cgi-bin/login.cgi, or (3) possibly certain parameters to d4d/alarms.php as demonstrated by the search_str parameter.

    Source:Trustwave's SpiderLabs
    Published:9 Jan 2020
    6.5
    Medium

    CVE-2012-1258

    Last Modified: 28 Jul 2012

    cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and selectedUserGroup parameters.

    Source:Trustwave's SpiderLabs
    Published:9 Jan 2020
    5.5
    Medium

    CVE-2012-1257

    Last Modified: 2 May 2015

    Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.

    Source:Dimitris Glynos
    Published:20 Dec 2011
    10
    Critical

    CVE-2012-1239

    Last Modified: 3 Mar 2015

    The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers to bypass authentication and obtain administrative privileges via unspecified vectors.

    Source:Deral Heiland PercX
    Published:6 Apr 2012
    7.5
    High

    CVE-2012-1226

    Last Modified: 13 Jul 2018

    Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the (1) file parameter to document.php or (2) backtopage parameter in a create action to comm/action/fiche.php.

    Source:Benjamin Kunz Mejri
    Published:21 Feb 2012
    7.5
    High

    CVE-2012-1225

    Last Modified: 13 Jul 2018

    Multiple SQL injection vulnerabilities in Dolibarr CMS 3.2.0 Alpha and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) memberslist parameter (aka Member List) in list.php or (2) rowid parameter to adherents/fiche.php.

    Source:Benjamin Kunz Mejri
    Published:21 Feb 2012
    4.3
    Medium

    CVE-2012-1224

    Last Modified: 30 Apr 2015

    Cross-site scripting (XSS) vulnerability in system/classes/login.php in ContentLion Alpha 1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:Stefan Schurtz
    Published:21 Feb 2012
    5
    Medium

    CVE-2012-1221

    Last Modified: 27 Apr 2015

    Directory traversal vulnerability in the telnet server in RabidHamster R2/Extreme 1.65 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the File command.

    Source:Luigi Auriemma
    Published:21 Feb 2012
    6.8
    Medium

    CVE-2012-1220

    Last Modified: 5 Feb 2012

    Cross-site request forgery (CSRF) vulnerability in modules/config/admin_utente.php in GAzie 5.20 and earlier allows remote attackers to hijack the authentication of administrators for requests that change account information via an update action, as demonstrated by changing the password.

    Source:Giuseppe D'Inverno
    Published:21 Feb 2012
    4.3
    Medium

    CVE-2012-1217

    Last Modified: 15 Apr 2015

    Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary web script or HTML via the team parameter to (1) prospects.php, (2) prospect.php, or (3) team.php.

    Source:Liyan Oz
    Published:20 Feb 2012
    4.3
    Medium

    CVE-2012-1213

    Last Modified: 10 Apr 2015

    Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before 6.0.15 and 7.x before 7.1.3 allows remote attackers to inject arbitrary web script or HTML via the view parameter.

    Source:sonyy
    Published:20 Feb 2012
    4.3
    Medium

    CVE-2012-1211

    Last Modified: 15 Apr 2015

    Cross-site scripting (XSS) vulnerability in pfile/kommentar.php in Powie pFile 1.02 allows remote attackers to inject arbitrary web script or HTML via the filecat parameter.

    Source:indoushka
    Published:20 Feb 2012
    7.5
    High

    CVE-2012-1210

    Last Modified: 15 Apr 2015

    SQL injection vulnerability in pfile/file.php in Powie pFile 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:indoushka
    Published:20 Feb 2012
    4.3
    Medium

    CVE-2012-1208

    Last Modified: 12 Feb 2012

    Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) report parameter to blog/settings or (2) error parameter to users/index.

    Source:Avram Marius
    Published:20 Feb 2012
    7.5
    High

    CVE-2012-1205

    Last Modified: 19 Sept 2011

    PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

    Source:Ben Schmidt
    Published:20 Feb 2012
    6.8
    Medium

    CVE-2012-1203

    Last Modified: 7 Dec 2016

    Cross-site request forgery (CSRF) vulnerability in starnet/index.php in SyndeoCMS 3.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add user accounts via a save_user action.

    Source:Ivano Binetti
    Published:28 Dec 2014
    7.5
    High

    CVE-2012-1200

    Last Modified: 10 Apr 2015

    Multiple PHP remote file inclusion vulnerabilities in Nova CMS allow remote attackers to execute arbitrary PHP code via a URL in the (1) fileType parameter to optimizer/index.php, (2) id parameter to administrator/modules/moduleslist.php, (3) filename parameter to includes/function/gets.php, or (4) conf[blockfile] parameter to includes/function/usertpl.php.

    Source:indoushka
    Published:18 Feb 2012
    7.5
    High

    CVE-2012-1199

    Last Modified: 14 Apr 2015

    Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) BASE_path parameter to base_ag_main.php, (2) base_db_setup.php, (3) base_graph_common.php, (4) base_graph_display.php, (5) base_graph_form.php, (6) base_graph_main.php, (7) base_local_rules.php, (8) base_logout.php, (9) base_main.php, (10) base_maintenance.php, (11) base_payload.php, (12) base_qry_alert.php, (13) base_qry_common.php, (14) base_qry_main.php, (15) base_stat_alerts.php, (16) base_stat_class.php, (17) base_stat_common.php, (18) base_stat_ipaddr.php, (19) base_stat_iplink.php, (20) base_stat_ports.php, (21) base_stat_sensor.php, (22) base_stat_time.php, (23) base_stat_uaddr.php, (24) base_user.php, (25) index.php, (26) admin/base_roleadmin.php, (27) admin/base_useradmin.php, (28) admin/index.php, (29) help/base_setup_help.php, (30) includes/base_action.inc.php, (31) includes/base_cache.inc.php, (32) includes/base_db.inc.php, (33) includes/base_db.inc.php, (34) includes/base_include.inc.php, (35) includes/base_output_html.inc.php, (36) includes/base_output_query.inc.php, (37) includes/base_state_criteria.inc.php, (38) includes/base_state_query.inc.php or (39) setup/base_conf_contents.php; (40) GLOBALS[user_session_path] parameter to includes/base_state_common.inc.php; (41) BASE_Language parameter to setup/base_conf_contents.php; or (42) ado_inc_php parameter to setup/setup2.php.

    Source:indoushka
    Published:18 Feb 2012