NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
44091  CVE-2012-2275  Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijack the authentication of users for requests that add, delete, or modify sensitive information, as demonstrated by changing the administrator"s email via an editUser action to lib/usermanagement/userInfo.php.    6.8  Medium  2017-01-19  2012-09-17  View
44603  CVE-2012-2912  Multiple cross-site scripting (XSS) vulnerabilities in the LeagueManager plugin 3.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter in the show-league page or (2) season parameter in the team page to wp-admin/admin.php.    4.3  Medium  2017-01-19  2012-05-22  View
44859  CVE-2012-3233  Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako Fusion 4.40.1148, and possibly before 4.50.1581, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.    4.3  Medium  2017-01-19  2012-09-17  View
45115  CVE-2012-3523  The STARTTLS implementation in nnrpd in INN before 2.5.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.    6.8  Medium  2017-01-19  2013-02-21  View
45371  CVE-2012-3832  Cross-site scripting (XSS) vulnerability in decoda/Decoda.php in Decoda before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to (1) b or (2) div tags.    4.3  Medium  2017-01-19  2012-07-17  View

Page 2151 of 17672, showing 5 records out of 88360 total, starting on record 10751, ending on 10755

Actions