NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 44984 | CVE-2012-3387 | Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check. | 2 | 4 | Medium | 2017-01-19 | 2012-07-24 | View | |
| 45496 | CVE-2012-4018 | Cross-site scripting (XSS) vulnerability in Final Beta Laboratory MyWebSearch before 1.23 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2013-01-24 | View | |
| 45752 | CVE-2012-4336 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) an arbitrary parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2012-09-20 | View | |
| 46008 | CVE-2012-4671 | psyced before 20120821 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via responses for domains that were not asserted. | 2 | 5.8 | Medium | 2017-01-19 | 2012-08-27 | View | |
| 47032 | CVE-2012-6081 | Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as exploited in the wild in July 2012. | 2 | 6 | Medium | 2017-01-19 | 2013-12-13 | View |
Page 15150 of 17672, showing 5 records out of 88360 total, starting on record 75746, ending on 75750