7.5
    High

    CVE-2012-1198

    Last Modified: 14 Apr 2015

    base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents of the file with an executable extension via a create action, then accessing it via a view action.

    Source:indoushka
    Published:18 Feb 2012
    5
    Medium

    CVE-2012-1196

    Last Modified: 8 Apr 2012

    Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a .. (dot dot) in the filename parameter in a SetTaskLogByFile SOAP request.

    Source:Metasploit
    Published:18 Feb 2012
    7.5
    High

    CVE-2012-1195

    Last Modified: 8 Apr 2012

    Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a PutUpdateFileCore command in a RunAMTCommand SOAP request, then accessing the file via a direct request to the file in the web root.

    Source:Metasploit
    Published:18 Feb 2012
    9.3
    Critical

    CVE-2012-1189

    Last Modified: 16 Mar 2012

    Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-assisted remote attackers to execute arbitrary code via a long file name in an engine sample attribute in an xml configuration file.

    Source:Andres Gomez & David Mora
    Published:8 Oct 2012
    4.3
    Medium

    CVE-2012-1188

    Last Modified: 4 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) type or (2) querystring parameters to private/en/error or (3) name parameter to private/en/locale/index.

    Source:anonymous
    Published:26 Sept 2012
    7.5
    High

    CVE-2012-1184

    Last Modified: 10 May 2012

    Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in an HTTP Digest Authentication header.

    Source:Russell Bryant
    Published:18 Sept 2012
    10
    Critical

    CVE-2012-1182

    Last Modified: 1 Dec 2016

    The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.

    Source:Metasploit
    Published:10 Apr 2012
    6.8
    Medium

    CVE-2012-1153

    Last Modified: 12 Jun 2012

    Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory.

    Source:Metasploit
    Published:6 Oct 2012
    6.8
    Medium

    CVE-2012-1125

    Last Modified: 23 Jan 2012

    Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with a PHP extension, then accessing it via a direct request to the file in the directory specified by the folder parameter.

    Source:EgiX
    Published:8 Oct 2012
    9.8
    Critical

    CVE-2012-1124

    Last Modified: 16 Mar 2012

    SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.

    Source:skysbsb
    Published:11 Feb 2020
    7.5
    High

    CVE-2012-1116

    Last Modified: 6 Nov 2017

    SQL injection vulnerability in Joomla! 1.7.x and 2.5.x before 2.5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Source:Colin Wong
    Published:26 Sept 2012
    6.8
    Medium

    CVE-2012-1112

    Last Modified: 5 May 2015

    Directory traversal vulnerability in Open-Realty CMS 2.5.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the select_users_template parameter to index.php.

    Source:Aung Khant
    Published:6 Sept 2012
    4.3
    Medium

    CVE-2012-1110

    Last Modified: 4 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) email, (3) email2, (4) f17_zip, or (5) agree parameter to join.php; (6) PATH_INFO, (7) st, (8) f17_city, (9) f17_country, (10) f17_state, (11) f17_zip, (12) f19, (13) wphoto, (14) search, or (15) v parameter to search.php; (16) PATH_INFO or (17) st parameter to photo_search.php; or (18) return parameter to photo_view.php.

    Source:Aung Khant
    Published:6 Sept 2012
    5.5
    Medium

    CVE-2012-1096

    Last Modified: 2 May 2015

    NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.

    Source:Ludwig
    Published:29 Feb 2012
    4.3
    Medium

    CVE-2012-1069

    Last Modified: 7 Apr 2015

    Cross-site scripting (XSS) vulnerability in module/kb/search_word in the search module in lknSupport allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:Red Security TEAM
    Published:14 Feb 2012
    4.3
    Medium

    CVE-2012-1065

    Last Modified: 19 Mar 2012

    Insecure method vulnerability in TuxScripting.dll in the TuxSystem ActiveX control in 2X ApplicationServer 10.1 Build 1224 allows remote attackers to create or overwrite arbitrary files via the ExportSettings method.

    Source:rgod
    Published:14 Feb 2012
    4.3
    Medium

    CVE-2012-1059

    Last Modified: 16 Mar 2012

    Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, as demonstrated using the "Front" field in the shirt module.

    Source:Vulnerability-Lab
    Published:14 Feb 2012
    6
    Medium

    CVE-2012-1058

    Last Modified: 3 Apr 2012

    Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an admin.newuser action to index.php.

    Source:Vaibhav Gupta
    Published:14 Feb 2012
    4.3
    Medium

    CVE-2012-1049

    Last Modified: 26 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainName parameter to jsp/AddDC.jsp or (2) operation parameter to DomainConfig.do.

    Source:LiquidWorm
    Published:13 Feb 2012
    4.3
    Medium

    CVE-2012-1048

    Last Modified: 8 Apr 2015

    Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.

    Source:Chokri B.A
    Published:12 Feb 2012
    7.5
    High

    CVE-2012-1047

    Last Modified: 8 Feb 2012

    Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter in an Online_help action.

    Source:Vulnerability-Lab
    Published:12 Feb 2012
    4.3
    Medium

    CVE-2012-1039

    Last Modified: 2 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7) page parameter to admin/plugin.php.

    Source:High-Tech Bridge SA
    Published:19 Mar 2012
    4.3
    Medium

    CVE-2012-1038

    Last Modified: 30 Jun 2015

    Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter name.

    Source:Craig Lambert
    Published:3 Apr 2013
    7.5
    High

    CVE-2012-1029

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in mobile/search/index.php in Tube Ace (Adult PHP Tube Script) 1.6 allows remote attackers to execute arbitrary SQL commands via the q parameter. NOTE: some of these details are obtained from third party information.

    Source:Daniel Godoy
    Published:8 Feb 2012
    4.3
    Medium

    CVE-2012-1028

    Last Modified: 8 Apr 2015

    Cross-site scripting (XSS) vulnerability in bin/index.php in SimpleGroupware 0.742 and other versions before 0.743 allows remote attackers to inject arbitrary web script or HTML via the export parameter.

    Source:Infoserve Security Team
    Published:8 Feb 2012
    4.3
    Medium

    CVE-2012-1027

    Last Modified: 7 Apr 2015

    Cross-site scripting (XSS) vulnerability in account-closed.tcl in ]project-open[ (aka ]po[) 3.4.x, 3.5.0.1-2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the message parameter to register/account-closed.

    Source:Michail Poultsakis
    Published:8 Feb 2012
    7.5
    High

    CVE-2012-1026

    Last Modified: 6 Feb 2012

    Multiple SQL injection vulnerabilities in login2.php in XRay CMS 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.

    Source:chap0
    Published:8 Feb 2012
    5
    Medium

    CVE-2012-1025

    Last Modified: 9 Jan 2012

    Absolute path traversal vulnerability in file in Enigma2 Webinterface 1.6.0 through 1.6.8, 1.6rc3, and 1.7.0 allows remote attackers to read arbitrary files via a full pathname in the file parameter.

    Source:Todor Donev
    Published:8 Feb 2012
    5
    Medium

    CVE-2012-1024

    Last Modified: 9 Jan 2012

    Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:Todor Donev
    Published:8 Feb 2012
    5.8
    Medium

    CVE-2012-1023

    Last Modified: 6 Apr 2015

    Open redirect vulnerability in admin/index.php in 4images 1.7.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter.

    Source:RandomStorm
    Published:8 Feb 2012
    7.5
    High

    CVE-2012-1022

    Last Modified: 6 Apr 2015

    SQL injection vulnerability in admin/categories.php in 4images 1.7.10 remote attackers to execute arbitrary SQL commands via the cat_parent_id parameter in an addcat action.

    Source:RandomStorm
    Published:8 Feb 2012
    4.3
    Medium

    CVE-2012-1021

    Last Modified: 6 Apr 2015

    Cross-site scripting (XSS) vulnerability in admin/categories.php in 4images 1.7.10 allows remote attackers to inject arbitrary web script or HTML via the cat_parent_id parameter in an addcat action.

    Source:RandomStorm
    Published:8 Feb 2012
    4.3
    Medium

    CVE-2012-1018

    Last Modified: 20 Dec 2016

    Cross-site scripting (XSS) vulnerability in includes/convert.php in D-Mack Media Currency Converter (mod_currencyconverter) module 1.0.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the from parameter.

    Source:BHG Security Center
    Published:8 Feb 2012
    7.5
    High

    CVE-2012-1017

    Last Modified: 6 Feb 2012

    Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary SQL commands via the (1) ip_addr[0][1], (2) ip_addr[0][2], or (3) ip_addr[0][9] parameters.

    Source:a.kadir altan
    Published:8 Feb 2012
    7.5
    High

    CVE-2012-1011

    Last Modified: 22 Jan 2012

    actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions to upload and execute arbitrary PHP code by setting the HTTP_REFERER to a certain value, then uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.

    Source:6Scan
    Published:7 Feb 2012
    7.5
    High

    CVE-2012-1010

    Last Modified: 22 Jan 2012

    Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.

    Source:6Scan
    Published:7 Feb 2012
    5
    Medium

    CVE-2012-1009

    Last Modified: 2 Feb 2012

    NetSarang Xlpd 4 Build 0100 and NetSarang Xmanager Enterprise 4 Build 0186 allow remote attackers to cause a denial of service (daemon crash) via a malformed LPD request.

    Source:SecPod Research
    Published:14 Feb 2012
    5
    Medium

    CVE-2012-1008

    Last Modified: 10 Oct 2016

    OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SIP INVITE message.

    Source:SecPod Research
    Published:8 Feb 2012
    4.3
    Medium

    CVE-2012-1007

    Last Modified: 2 Feb 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.

    Source:SecPod Research
    Published:1 Feb 2012
    4.3
    Medium

    CVE-2012-1006

    Last Modified: 2 Feb 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.

    Source:SecPod Research
    Published:1 Feb 2012
    4.3
    Medium

    CVE-2012-1005

    Last Modified: 16 Mar 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Sphinx Software Mobile Web Server 3.1.2.47 allow remote attackers to inject arbitrary web script or HTML via the comment parameter to a blog, as demonstrated using (1) Blog/MyFirstBlog.txt or (2) Blog/AboutSomething.txt.

    Source:SecPod Research
    Published:7 Feb 2012
    10
    Critical

    CVE-2012-1002

    Last Modified: 2 May 2012

    SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Source:EgiX
    Published:8 Feb 2012
    6.1
    Medium

    CVE-2012-1001

    Last Modified: 1 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) content parameter to includes/ajax.php or (2) body parameter to includes/error.php.

    Source:High-Tech Bridge SA
    Published:21 Nov 2019
    6.8
    Medium

    CVE-2012-0997

    Last Modified: 17 Apr 2015

    Cross-site request forgery (CSRF) vulnerability in admin/index.php in 11in1 1.2.1 stable 12-31-2011 allows remote attackers to hijack the authentication of administrators for requests that add new topics via an addTopic action.

    Source:High-Tech Bridge SA
    Published:20 Feb 2012
    5
    Medium

    CVE-2012-0996

    Last Modified: 17 Apr 2015

    Multiple directory traversal vulnerabilities in 11in1 1.2.1 stable 12-31-2011 allow remote attackers to read arbitrary files via a .. (dot dot) in the class parameter to (1) index.php or (2) admin/index.php.

    Source:High-Tech Bridge SA
    Published:20 Feb 2012
    8.5
    High

    CVE-2012-0992

    Last Modified: 6 Apr 2015

    interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file parameter.

    Source:High-Tech Bridge SA
    Published:7 Feb 2012
    3.5
    Low

    CVE-2012-0991

    Last Modified: 6 Apr 2015

    Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formname parameter to (1) contrib/acog/print_form.php; or (2) load_form.php, (3) view_form.php, or (4) trend_form.php in interface/patient_file/encounter.

    Source:High-Tech Bridge SA
    Published:7 Feb 2012
    3.5
    Low

    CVE-2012-0990

    Last Modified: 3 Apr 2015

    Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify account settings such as the administrator password or email via certain Settings[] parameters.

    Source:High-Tech Bridge SA
    Published:7 Feb 2012
    4.3
    Medium

    CVE-2012-0989

    Last Modified: 1 Apr 2015

    Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

    Source:High-Tech Bridge SA
    Published:1 Oct 2012
    4.3
    Medium

    CVE-2012-0988

    Last Modified: 30 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in config/dmsDefaults.php in KnowledgeTree 3.7.0.2 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) login.php, (2) admin.php, or (3) preferences.php.

    Source:High-Tech Bridge SA
    Published:20 Sept 2012