NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
46123  CVE-2012-4851  Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.    4.3  Medium  2017-01-19  2013-02-25  View
46379  CVE-2012-5169  Multiple cross-site scripting (XSS) vulnerabilities in file_manager/preview_top.php in ATutor AContent before 1.2-2 allow remote attackers to inject arbitrary web script or HTML via the (1) pathext, (2) popup, (3) framed, or (4) file parameter.    4.3  Medium  2017-01-19  2013-03-01  View
46635  CVE-2012-5507  AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.    4.3  Medium  2017-01-19  2014-10-02  View
46891  CVE-2012-5868  WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator"s logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.    2.6  Low  2017-01-19  2013-01-08  View
47147  CVE-2012-6433  Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of administrators for requests that conduct XSS attacks via the news_title parameter in a create action.    6.8  Medium  2017-01-19  2013-01-07  View

Page 2632 of 17672, showing 5 records out of 88360 total, starting on record 13156, ending on 13160

Actions