NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 44364 | CVE-2012-2641 | Cross-site scripting (XSS) vulnerability in Zenphoto before 1.4.3 allows remote attackers to inject arbitrary web script or HTML by triggering improper interaction with an unspecified library. | 2 | 4.3 | Medium | 2017-01-19 | 2012-07-06 | View | |
| 44620 | CVE-2012-2930 | Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an adduser action to admin/index.php or (2) conduct static PHP code injection attacks in .htusers.php via the user parameter to admin/index.php. | 2 | 6.8 | Medium | 2017-01-19 | 2015-04-27 | View | |
| 44876 | CVE-2012-3257 | HP Business Availability Center (BAC) 8.07 allows remote authenticated users to hijack web sessions via unspecified vectors. | 2 | 4.6 | Medium | 2017-01-19 | 2013-03-21 | View | |
| 45644 | CVE-2012-4198 | The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 has a different outcome for a groups request depending on whether a group exists, which allows remote authenticated users to discover private group names by observing whether a call throws an error. | 2 | 4 | Medium | 2017-01-19 | 2013-12-13 | View | |
| 46156 | CVE-2012-4890 | Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS 2011 08.09.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) comment to the news, (2) title to the news, or (3) the folder names in a gallery. | 2 | 4.3 | Medium | 2017-01-19 | 2012-09-11 | View |
Page 2752 of 17672, showing 5 records out of 88360 total, starting on record 13756, ending on 13760