NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 46123 | CVE-2012-4851 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI. | 2 | 4.3 | Medium | 2017-01-19 | 2013-02-25 | View | |
| 46379 | CVE-2012-5169 | Multiple cross-site scripting (XSS) vulnerabilities in file_manager/preview_top.php in ATutor AContent before 1.2-2 allow remote attackers to inject arbitrary web script or HTML via the (1) pathext, (2) popup, (3) framed, or (4) file parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2013-03-01 | View | |
| 46635 | CVE-2012-5507 | AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation. | 2 | 4.3 | Medium | 2017-01-19 | 2014-10-02 | View | |
| 46891 | CVE-2012-5868 | WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator"s logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack. | 2 | 2.6 | Low | 2017-01-19 | 2013-01-08 | View | |
| 47147 | CVE-2012-6433 | Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of administrators for requests that conduct XSS attacks via the news_title parameter in a create action. | 2 | 6.8 | Medium | 2017-01-19 | 2013-01-07 | View |
Page 2632 of 17672, showing 5 records out of 88360 total, starting on record 13156, ending on 13160