NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
44364  CVE-2012-2641  Cross-site scripting (XSS) vulnerability in Zenphoto before 1.4.3 allows remote attackers to inject arbitrary web script or HTML by triggering improper interaction with an unspecified library.    4.3  Medium  2017-01-19  2012-07-06  View
44620  CVE-2012-2930  Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an adduser action to admin/index.php or (2) conduct static PHP code injection attacks in .htusers.php via the user parameter to admin/index.php.    6.8  Medium  2017-01-19  2015-04-27  View
44876  CVE-2012-3257  HP Business Availability Center (BAC) 8.07 allows remote authenticated users to hijack web sessions via unspecified vectors.    4.6  Medium  2017-01-19  2013-03-21  View
45644  CVE-2012-4198  The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 has a different outcome for a groups request depending on whether a group exists, which allows remote authenticated users to discover private group names by observing whether a call throws an error.    Medium  2017-01-19  2013-12-13  View
46156  CVE-2012-4890  Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS 2011 08.09.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) comment to the news, (2) title to the news, or (3) the folder names in a gallery.    4.3  Medium  2017-01-19  2012-09-11  View

Page 2752 of 17672, showing 5 records out of 88360 total, starting on record 13756, ending on 13760

Actions